CVE-2024-27899
HIGHNetWeaver AS Java - Info Disclosure
Title source: llmDescription
Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper security requirements for the content of the newly defined security answer. This can be leveraged by an attacker to cause profound impact on confidentiality and low impact on both integrity and availability.
Scores
CVSS v3
8.8
EPSS
0.0012
EPSS Percentile
30.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L
Classification
CWE
CWE-640
Status
draft
Timeline
Published
Apr 09, 2024
Tracked Since
Feb 18, 2026