CVE-2015-2817

SAP NetWeaver 7.40 - Exposure of Sensitive Information via ReadProfile Parameters

Title source: llm
STIX 2.1

Description

The SAP Management Console in SAP NetWeaver 7.40 allows remote attackers to obtain sensitive information via the ReadProfile parameters, aka SAP Security Note 2091768.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/73705
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/535829/100/800/threaded
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Jun/65

Scores

EPSS 0.0043
EPSS Percentile 63.0%

Details

CWE
CWE-200
Status published
Products (1)
sap/netweaver 7.40
Published Apr 01, 2015
Tracked Since Feb 18, 2026