6.5 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
6.6 Medium
AI Score
Confidence
High
0.001 Low
EPSS
Percentile
32.2%
The Message Display Tool (MDT) of SAP NetWeaver Process Integration - version SAP_XIAF 7.50, does not perform authentication checks for certain functionalities that require user identity. An unauthenticated user might access technical data about the product status and its configuration. The vulnerability does not allow access to sensitive information or administrative functionalities. On successful exploitation an attacker can cause limited impact on confidentiality and availability of the application.
CPE | Name | Operator | Version |
---|---|---|---|
sap:netweaver_process_integration | sap netweaver process integration | eq | 7.50 |
[
{
"defaultStatus": "unaffected",
"product": "SAP NetWeaver Process Integration (Message Display Tool)",
"vendor": "SAP_SE",
"versions": [
{
"status": "affected",
"version": "SAP_XIAF 7.50"
}
]
}
]
6.5 Medium
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
6.6 Medium
AI Score
Confidence
High
0.001 Low
EPSS
Percentile
32.2%