ID

VAR-201611-0433


TITLE

SAP NetWeaver Java AS 'Webdynpro' Component Information Disclosure Vulnerability

Trust: 0.3

sources: BID: 94174

DESCRIPTION

SAP NetWeaver is prone to an information-disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may lead to further attacks. SAP Netweaver 7.5 is vulnerable.

Trust: 0.3

sources: BID: 94174

AFFECTED PRODUCTS

vendor:sapmodel:netweaverscope:eqversion:7.5

Trust: 0.3

sources: BID: 94174

THREAT TYPE

network

Trust: 0.3

sources: BID: 94174

TYPE

Design Error

Trust: 0.3

sources: BID: 94174

EXTERNAL IDS

db:BIDid:94174

Trust: 0.3

sources: BID: 94174

REFERENCES

url:http://www.sap.com

Trust: 0.3

url:www.sap.com/platform/netweaver

Trust: 0.3

url:https://service.sap.com/sap/support/notes/2342940

Trust: 0.3

url:https://erpscan.com/advisories/erpscan-16-039-sap-netweaver-7-5-information-disclosure-port-scan-sld-test-application/

Trust: 0.3

sources: BID: 94174

CREDITS

Mathieu Geli (ERPScan)

Trust: 0.3

sources: BID: 94174

SOURCES

db:BIDid:94174

LAST UPDATE DATE

2022-05-17T01:41:08.864000+00:00


SOURCES UPDATE DATE

db:BIDid:94174date:2016-11-24T01:08:00

SOURCES RELEASE DATE

db:BIDid:94174date:2016-11-08T00:00:00