CVE-2024-25645: Information Disclosure vulnerability in SAP NetWeaver (Enterprise Portal)
Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which would otherwise be restricted causing low impact on confidentiality of the application and with no impact on Integrity and Availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25645?
CVE-2024-25645 has a low impact on confidentiality, with no impact on integrity and availability.
How do I fix CVE-2024-25645?
To address CVE-2024-25645, update your SAP NetWeaver (Enterprise Portal) to the latest version as recommended by SAP.
What versions of SAP are affected by CVE-2024-25645?
CVE-2024-25645 specifically affects SAP NetWeaver (Enterprise Portal) version 7.50.
What kind of information is exposed due to CVE-2024-25645?
CVE-2024-25645 allows unauthorized access to restricted information within SAP NetWeaver (Enterprise Portal).
Is there a workaround for CVE-2024-25645 if I cannot update immediately?
While an immediate update is recommended, implementing strict access controls may mitigate some exposure related to CVE-2024-25645.