CVE-2023-24527
MEDIUMSAP NetWeaver AS Java for Deploy Service -7.5 - Info Disclosure
Title source: llmDescription
SAP NetWeaver AS Java for Deploy Service - version 7.5, does not perform any access control checks for functionalities that require user identity enabling an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access a service which will enable them to access but not modify server settings and data with no effect on availability and integrity.
References (2)
Core 2
Core References
Permissions Required
https://launchpad.support.sap.com/#/notes/3287784
Scores
CVSS v3
5.3
EPSS
0.0034
EPSS Percentile
57.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-306
Status
published
Products (1)
sap/netweaver_as_java_for_deploy_service
7.5
Published
Apr 11, 2023
Tracked Since
Feb 18, 2026