First published: Tue Nov 14 2023(Updated: )
The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to identify the legitimate user ids. This will have an impact on confidentiality but there is no other impact on integrity or availability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver Application Server Java | =7.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-42480.
The title of the vulnerability is Information Disclosure in NetWeaver AS Java Logon.
This vulnerability has an impact on confidentiality but there is no other impact on integrity or availability.
The affected software is SAP NetWeaver Application Server Java version 7.50.
The severity of this vulnerability is medium (CVSS score: 5.3).
An unauthenticated attacker can brute force the login functionality of NetWeaver AS Java Logon application version 7.50 to identify legitimate user IDs.
Yes, please refer to the official SAP notes and documentation for the recommended fix.