SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targeting internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. Thus, having a low impact on confidentiality.
Under certain conditions SAP Gateway of ABAP Application Server (fixed in SAPGWFND 7.5, 7.51, 7.52, 7.53; SAPBASIS 7.5) allows an attacker to access information which would otherwise be restricted.