Description


SAP Internet Communication framework (ICM) - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 785, allows an attacker with logon functionality, to exploit the authentication function by using POST and form field to repeat executions of the initial command by a GET request and exposing sensitive data. This vulnerability is normally exposed over the network and successful exploitation can lead to exposure of data like system details.

Related CPE's


a

sap

netweaver_abap

14

a

sap

netweaver_application_server_abap

14

Weaknesses



CWE-668


CWE-668

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

4.3 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2021-10-12T13:15:09.267Z

4 years ago

Last modified

2024-11-21T05:24:15.753Z

1 year ago