CVE-2015-8840: High severity sap netweaver as for java vulnerability
The XML Data Archiving Service (XML DAS) in SAP NetWeaver AS Java does not check authorization, which allows remote authenticated users to obtain sensitive information, gain privileges, or possibly have unspecified other impact via requests to (1) webcontent/cas/casenter.jsp, (2) webcontent/cas/casvalidate.jsp, or (3) webcontent/aas/aasstore.jsp, aka SAP Security Note 1945215.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8840?
CVE-2015-8840 has a high severity rating due to the potential for unauthorized access to sensitive information and privilege escalation.
How do I fix CVE-2015-8840?
To fix CVE-2015-8840, ensure that proper authorization checks are implemented in the XML Data Archiving Service of SAP NetWeaver AS Java.
Who is affected by CVE-2015-8840?
CVE-2015-8840 affects users of SAP NetWeaver AS Java who may encounter unsecured access to the XML Data Archiving Service.
What impact could CVE-2015-8840 have on my system?
CVE-2015-8840 could allow remote authenticated users to gain unauthorized access to sensitive data or escalate privileges.
When was CVE-2015-8840 reported?
CVE-2015-8840 was reported in July 2015 as part of a broader security advisory from SAP.