2025-03-16 03:03:50 +00:00

64 lines
2.0 KiB
JSON

{
"id": "CVE-2025-23194",
"sourceIdentifier": "cna@sap.com",
"published": "2025-03-11T01:15:34.630",
"lastModified": "2025-03-11T01:15:34.630",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "SAP NetWeaver Enterprise Portal OBN does not perform proper authentication check for a particular configuration setting. As result, a non-authenticated user can set it to an undesired value causing low impact on integrity. There is no impact on confidentiality or availability of the application."
},
{
"lang": "es",
"value": "SAP NetWeaver Enterprise Portal OBN no realiza una comprobaci\u00f3n de autenticaci\u00f3n adecuada para una configuraci\u00f3n en particular. Como resultado, un usuario no autenticado puede configurarlo con un valor no deseado, lo que tiene un impacto bajo en la integridad. No hay impacto en la confidencialidad o disponibilidad de la aplicaci\u00f3n."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "cna@sap.com",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"baseScore": 5.3,
"baseSeverity": "MEDIUM",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4
}
]
},
"weaknesses": [
{
"source": "cna@sap.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-306"
}
]
}
],
"references": [
{
"url": "https://me.sap.com/notes/3561792",
"source": "cna@sap.com"
},
{
"url": "https://url.sap/sapsecuritypatchday",
"source": "cna@sap.com"
}
]
}