First published: Fri Apr 08 2016(Updated: )
The XML Data Archiving Service (XML DAS) in SAP NetWeaver AS Java does not check authorization, which allows remote authenticated users to obtain sensitive information, gain privileges, or possibly have unspecified other impact via requests to (1) webcontent/cas/cas_enter.jsp, (2) webcontent/cas/cas_validate.jsp, or (3) webcontent/aas/aas_store.jsp, aka SAP Security Note 1945215.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver Java Application Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8840 has a high severity rating due to the potential for unauthorized access to sensitive information and privilege escalation.
To fix CVE-2015-8840, ensure that proper authorization checks are implemented in the XML Data Archiving Service of SAP NetWeaver AS Java.
CVE-2015-8840 affects users of SAP NetWeaver AS Java who may encounter unsecured access to the XML Data Archiving Service.
CVE-2015-8840 could allow remote authenticated users to gain unauthorized access to sensitive data or escalate privileges.
CVE-2015-8840 was reported in July 2015 as part of a broader security advisory from SAP.