SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to gain unauthorized access to system information. By using a specific URL parameter, an unauthenticated attacker could retrieve details such as system configuration. This has a limited impact on the confidentiality of the application and may be leveraged to facilitate further attacks or exploits.
History

Tue, 14 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jan 2025 00:45:00 +0000

Type Values Removed Values Added
Description SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to gain unauthorized access to system information. By using a specific URL parameter, an unauthenticated attacker could retrieve details such as system configuration. This has a limited impact on the confidentiality of the application and may be leveraged to facilitate further attacks or exploits.
Title Information Disclosure Vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
Weaknesses CWE-209
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-01-14T00:08:21.600Z

Updated: 2025-01-14T15:01:44.276Z

Reserved: 2024-12-05T21:37:23.093Z

Link: CVE-2025-0053

cve-icon Vulnrichment

Updated: 2025-01-14T15:01:40.347Z

cve-icon NVD

Status : Received

Published: 2025-01-14T01:15:15.403

Modified: 2025-01-14T01:15:15.403

Link: CVE-2025-0053

cve-icon Redhat

No data.