2024-09-28 23:58:16 +00:00

64 lines
2.1 KiB
JSON

{
"id": "CVE-2024-25645",
"sourceIdentifier": "cna@sap.com",
"published": "2024-03-12T01:15:49.780",
"lastModified": "2024-09-28T23:15:13.020",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Under certain condition\u00a0SAP\u00a0NetWeaver (Enterprise Portal) - version 7.50\u00a0allows an attacker to access information which would otherwise be restricted causing low impact on confidentiality of the application and with no impact on Integrity and Availability of the application."
},
{
"lang": "es",
"value": "Bajo ciertas condiciones, SAP NetWeaver (Enterprise Portal): la versi\u00f3n 7.50 permite a un atacante acceder a informaci\u00f3n que de otro modo estar\u00eda restringida, lo que causa un impacto bajo en la confidencialidad de la aplicaci\u00f3n y sin impacto en la integridad y disponibilidad de la aplicaci\u00f3n."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "cna@sap.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4
}
]
},
"weaknesses": [
{
"source": "cna@sap.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-732"
}
]
}
],
"references": [
{
"url": "https://me.sap.com/notes/3428847",
"source": "cna@sap.com"
},
{
"url": "https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364",
"source": "cna@sap.com"
}
]
}