Lucene search

K
cve[email protected]CVE-2015-2817
HistoryApr 01, 2015 - 2:59 p.m.

CVE-2015-2817

2015-04-0114:59:15
CWE-200
web.nvd.nist.gov
24
sap
management console
sap netweaver
remote attackers
sensitive information
cve-2015-2817
nvd
security
2091768

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.2 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

77.0%

The SAP Management Console in SAP NetWeaver 7.40 allows remote attackers to obtain sensitive information via the ReadProfile parameters, aka SAP Security Note 2091768.

Affected configurations

NVD
Node
sapnetweaverMatch7.40
CPENameOperatorVersion
sap:netweaversap netweavereq7.40

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.2 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

77.0%