CVE-2016-10005: Infoleak
Webdynpro in SAP Solman 7.1 through 7.31 allows remote attackers to obtain sensitive information via webdynpro/dispatcher/sap.com/caf~eu~gp~example~timeoff~wd requests, aka SAP Security Note 2344524.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10005?
CVE-2016-10005 is classified as a medium severity vulnerability due to its potential for sensitive information disclosure.
How do I fix CVE-2016-10005?
To remediate CVE-2016-10005, apply the patches provided in SAP Security Note 2344524 for the affected versions of SAP Solution Manager.
What software versions are affected by CVE-2016-10005?
CVE-2016-10005 affects SAP Solution Manager versions 7.1 through 7.31, including specific support packages.
Can CVE-2016-10005 be exploited remotely?
Yes, CVE-2016-10005 can be exploited remotely, allowing attackers to gain unauthorized access to sensitive information.
Is there a workaround for CVE-2016-10005?
Currently, the best approach for CVE-2016-10005 is to update to the patched versions, as no specific workaround is documented.