First published: Thu Jul 31 2014(Updated: )
The SAP Netweaver Business Warehouse component does not properly restrict access to the functions in the BW-SYS-DB-DB4 function group, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Netweaver Business Warehouse |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-5174 has been assigned a medium severity rating due to improper access control allowing unauthorized information access.
To fix CVE-2014-5174, ensure that proper access controls are implemented for the BW-SYS-DB-DB4 function group within SAP Netweaver Business Warehouse.
Users of SAP Netweaver Business Warehouse are susceptible to CVE-2014-5174 if proper access restrictions are not in place.
CVE-2014-5174 may allow remote authenticated users to access sensitive information that should be restricted.
Check for vendor recommendations and updates from SAP for any patches addressing CVE-2014-5174.