VulnerabilityAnalyzed
CVE-2024-25645
Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which would otherwise be restricted causing low impact on confidentiality of the application and with no impact on Integrity and…
MEDIUM 5.3EPSS 0.41%
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which would otherwise be restricted causing low impact on confidentiality of the application and with no impact on Integrity and Availability of the application.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.41% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-732
- Affected
- sap/netweaver enterprise portal
- Source
- cna@sap.com
References
- https://me.sap.com/notes/3428847Permissions Required
- https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364Vendor Advisory
- https://me.sap.com/notes/3428847Permissions Required
- https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.