CVE-2024-25644: Information Disclosure vulnerability in NetWeaver (WSRM)
Published Mar 12, 2024
·Updated
Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwise be restricted, causing low impact on Confidentiality with no impact on Integrity and Availability of the application.
Affected Software
2 affected components
SAP NetWeaver=7.50
SAP NetWeaver WSRM
Event History
Mar 12, 2024
CVE Published
via MITRE·12:33 AM
Data Sourced
via MITRE·12:33 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-25644?
CVE-2024-25644 has a low severity level affecting confidentiality.
2
How do I fix CVE-2024-25644?
To fix CVE-2024-25644, ensure you have applied the latest security patches provided by SAP for NetWeaver WSRM.
3
What information can be accessed due to CVE-2024-25644?
Due to CVE-2024-25644, an attacker may gain access to restricted information within SAP NetWeaver WSRM.
4
Is there any impact on integrity or availability with CVE-2024-25644?
CVE-2024-25644 poses no risk to the integrity or availability of the SAP NetWeaver WSRM application.
5
Which version of the software is affected by CVE-2024-25644?
CVE-2024-25644 specifically affects SAP NetWeaver WSRM version 7.50.