CVE-2019-0338: Infoleak
Published Aug 14, 2019
·Updated
During an OData V2/V4 request in SAP Gateway, versions 750, 751, 752, 753, the HTTP Header attributes cache-control and pragma were not properly set, allowing an attacker to access restricted information, resulting in Information Disclosure.
Affected Software
4 affected components
SAP Gateway=750
SAP Gateway=751
SAP Gateway=752
SAP Gateway=753
Event History
Aug 14, 2019
CVE Published
via MITRE·01:49 PM
Data Sourced
via MITRE·01:49 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the OData request issue in SAP Gateway?
The vulnerability ID for this issue is CVE-2019-0338.
2
Which versions of SAP Gateway are affected by this vulnerability?
Versions 750, 751, 752, 753 of SAP Gateway are affected by this vulnerability.
3
What is the severity of vulnerability CVE-2019-0338?
The severity of vulnerability CVE-2019-0338 is medium (5.3).
4
How does this vulnerability occur?
This vulnerability occurs during an OData V2/V4 request in SAP Gateway when the HTTP Header attributes cache-control and pragma are not properly set.
5
What is the impact of this vulnerability?
This vulnerability allows an attacker to access restricted information, resulting in information disclosure.