CyberSec.Space Logo
返回 CVE 浏览器

CVE-2019-0345

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.1540%
EPSS Percentile4.32th
Published2019年8月14日
Last Modified2024年11月21日

Vulnerability Description

A remote unauthenticated attacker can abuse a web service in SAP NetWeaver Application Server for Java (Administrator System Overview), versions 7.30, 7.31, 7.40, 7.50, by sending a specially crafted XML file and trick the application server into leaking authentication credentials for its own SAP Management console, resulting in Server-Side Request Forgery.

Affected Platforms (CPE)

📦
Sap

Netweaver Application Server Java

= 7.30
📦
Sap

Netweaver Application Server Java

= 7.31
📦
Sap

Netweaver Application Server Java

= 7.40
📦
Sap

Netweaver Application Server Java

= 7.50

References & Advisories

相关漏洞威胁