CVE-2014-1960

SAP NetWeaver Solution Manager - Unauthenticated Information Disclosure

Title source: llm
STIX 2.1

Description

The Solution Manager in SAP NetWeaver does not properly restrict access, which allows remote attackers to obtain sensitive information via unspecified vectors.

References (5)

Core 5
Core References
Various Sources x_refsource_confirm
https://service.sap.com/sap/support/notes/1828885
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/91093
Various Sources x_refsource_confirm
http://scn.sap.com/docs/DOC-8218
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/56942

Scores

EPSS 0.0036
EPSS Percentile 58.0%

Details

CWE
CWE-264
Status published
Products (3)
sap/netweaver
sap/netweaver_solution_manager 7.0
sap/netweaver_solution_manager 7.1
Published Feb 14, 2014
Tracked Since Feb 18, 2026