CVE-2023-42480: Information Disclosure in NetWeaver AS Java Logon
The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to identify the legitimate user ids. This will have an impact on confidentiality but there is no other impact on integrity or availability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-42480.
What is the title of the vulnerability?
The title of the vulnerability is Information Disclosure in NetWeaver AS Java Logon.
What is the impact of this vulnerability?
This vulnerability has an impact on confidentiality but there is no other impact on integrity or availability.
What is the affected software?
The affected software is SAP NetWeaver Application Server Java version 7.50.
What is the severity of this vulnerability?
The severity of this vulnerability is medium (CVSS score: 5.3).
How can an attacker exploit this vulnerability?
An unauthenticated attacker can brute force the login functionality of NetWeaver AS Java Logon application version 7.50 to identify legitimate user IDs.
Is there a fix for this vulnerability?
Yes, please refer to the official SAP notes and documentation for the recommended fix.