First published: Tue Mar 12 2024(Updated: )
Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which would otherwise be restricted causing low impact on confidentiality of the application and with no impact on Integrity and Availability of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver (Enterprise Portal) | ||
SAP NetWeaver (Enterprise Portal) | =7.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25645 has a low impact on confidentiality, with no impact on integrity and availability.
To address CVE-2024-25645, update your SAP NetWeaver (Enterprise Portal) to the latest version as recommended by SAP.
CVE-2024-25645 specifically affects SAP NetWeaver (Enterprise Portal) version 7.50.
CVE-2024-25645 allows unauthorized access to restricted information within SAP NetWeaver (Enterprise Portal).
While an immediate update is recommended, implementing strict access controls may mitigate some exposure related to CVE-2024-25645.