CVE-2019-0318

MEDIUM

SAP NetWeaver Application Server for Java - Info Disclosure

Title source: llm
STIX 2.1

Description

Under certain conditions SAP NetWeaver Application Server for Java (Startup Framework), versions 7.21, 7.22, 7.45, 7.49, and 7.53, allows an attacker to access information which would otherwise be restricted.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/109069
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2738791

Scores

CVSS v3 5.3
EPSS 0.0033
EPSS Percentile 55.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (5)
sap/netweaver_application_server_java 7.21
sap/netweaver_application_server_java 7.22
sap/netweaver_application_server_java 7.45
sap/netweaver_application_server_java 7.49
sap/netweaver_application_server_java 7.53
Published Jul 10, 2019
Tracked Since Feb 18, 2026