SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-2817

The SAP Management Console in SAP NetWeaver 7.40 allows remote attackers to obtain sensitive information via the ReadProfile parameters, aka SAP Security Note 2091768.

MEDIUM 5.0EPSS 2.38%

Does this matter?

Lower severity and a low EPSS score (2.38%). Track it; it rarely justifies an emergency change on its own.

Description

The SAP Management Console in SAP NetWeaver 7.40 allows remote attackers to obtain sensitive information via the ReadProfile parameters, aka SAP Security Note 2091768.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
2.38% probability · 83th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
sap/netweaver
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.