CVE-2024-28164
MEDIUMSAP NetWeaver AS Java - Unauthenticated Exposure of Sensitive Information via CAF Guided Procedures
Title source: llmDescription
SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensitive information about the server which would otherwise be restricted causing low impact on confidentiality of the application.
References (2)
Core 2
Core References
Permissions Required
https://me.sap.com/notes/3425571
Scores
CVSS v3
5.3
EPSS
0.0051
EPSS Percentile
66.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-200
Status
published
Products (1)
sap/netweaver_application_server_java
gp-core_7.5
Published
Jun 11, 2024
Tracked Since
Feb 18, 2026