Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-42480


The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to identify the legitimate user ids. This will have an impact on confidentiality but there is no other impact on integrity or availability.


Published

2023-11-14T01:15:07.907

Last Modified

2024-11-21T08:22:38.427

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-307

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap netweaver_application_server_java 7.50 Yes

References