CVE-2023-29111: Information Disclosure vulnerability in SAP Application Interface Framework (ODATA service)
Published Apr 11, 2023
·Updated
The SAP AIF (ODATA service) - versions 755, 756, discloses more detailed information than is required. An authorized attacker can use the collected information possibly to exploit the component. As a result, an attacker can cause a low impact on the confidentiality of the application.
Affected Software
2 affected components
SAP Application Interface Framework=755
SAP Application Interface Framework=756
Event History
Apr 11, 2023
CVE Published
via MITRE·03:01 AM
Data Sourced
via MITRE·03:01 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-29111.
2
What is the title of the vulnerability?
The title of the vulnerability is 'The SAP AIF (ODATA service) - versions 755 756 discloses more detailed information than is required.'
3
What is the severity of CVE-2023-29111?
The severity of CVE-2023-29111 is medium with a severity value of 4.3.
4
How does CVE-2023-29111 affect SAP Application Interface Framework?
CVE-2023-29111 affects SAP Application Interface Framework versions 755 and 756.
5
How can an attacker exploit CVE-2023-29111?
An authorized attacker can use the collected information from CVE-2023-29111 to possibly exploit the SAP AIF (ODATA service) component.