Description
SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality in order to identify the legitimate user IDs. This has an impact on confidentiality but not on integrity or availability.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-42536 | SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality in order to identify the legitimate user IDs. This has an impact on confidentiality but not on integrity or availability. |
References
History
Tue, 12 Nov 2024 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap netweaver Application Server Java |
|
| CPEs | cpe:2.3:a:sap:netweaver_application_server_java:7.5:*:*:*:*:*:*:* | |
| Vendors & Products |
Sap
Sap netweaver Application Server Java |
|
| Metrics |
ssvc
|
Tue, 12 Nov 2024 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality in order to identify the legitimate user IDs. This has an impact on confidentiality but not on integrity or availability. | |
| Title | Information Disclosure Vulnerability in SAP NetWeaver Application Server Java (Logon Application) | |
| Weaknesses | CWE-307 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-11-12T01:40:11.797Z
Reserved: 2024-09-27T20:05:59.021Z
Link: CVE-2024-47592
Updated: 2024-11-12T01:40:07.097Z
Status : Deferred
Published: 2024-11-12T01:15:05.210
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-47592
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD