First published: Wed Nov 13 2019(Updated: )
Under certain conditions SAP NetWeaver AS Java (corrected in 7.10, 7.20, 7.30, 7.31, 7.40, 7.50) allows an attacker to access information which would otherwise be restricted.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver Application Server Java | =7.10 | |
SAP NetWeaver Application Server Java | =7.20 | |
SAP NetWeaver Application Server Java | =7.30 | |
SAP NetWeaver Application Server Java | =7.31 | |
SAP NetWeaver Application Server Java | =7.40 | |
SAP NetWeaver Application Server Java | =7.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this SAP NetWeaver AS Java vulnerability is CVE-2019-0391.
The severity of CVE-2019-0391 vulnerability is medium (4.3).
Versions 7.10, 7.20, 7.30, 7.31, 7.40, and 7.50 of SAP NetWeaver AS Java are affected by CVE-2019-0391.
Under certain conditions, an attacker can exploit CVE-2019-0391 vulnerability to access restricted information in SAP NetWeaver AS Java.
Yes, the vulnerability has been corrected in versions 7.10, 7.20, 7.30, 7.31, 7.40, and 7.50 of SAP NetWeaver AS Java.