CVE-2015-2817: Infoleak
Published Apr 1, 2015
·Updated
The SAP Management Console in SAP NetWeaver 7.40 allows remote attackers to obtain sensitive information via the ReadProfile parameters, aka SAP Security Note 2091768.
Affected Software
1 affected component
SAP NetWeaver=7.40
Event History
Apr 1, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2817?
CVE-2015-2817 is rated as a medium severity vulnerability.
2
How do I fix CVE-2015-2817?
To fix CVE-2015-2817, apply SAP Security Note 2091768 to mitigate information disclosure risks.
3
What type of attack can exploit CVE-2015-2817?
CVE-2015-2817 can be exploited through remote attacks to gain unauthorized access to sensitive information.
4
Which software versions are affected by CVE-2015-2817?
CVE-2015-2817 affects SAP NetWeaver version 7.40.
5
What information can be disclosed by exploiting CVE-2015-2817?
Exploitation of CVE-2015-2817 can lead to the disclosure of sensitive configuration information.