Vulnerability Name: | CCN-66812 | ||||||
Published: | 2011-04-15 | ||||||
Updated: | 2011-04-15 | ||||||
Summary: | SAP NetWeaver Portal could allow a remote attacker to obtain sensitive information. An attacker could send a specially-crafted URL request using an invalid parameter to cause an error message to be returned containing the full installation path. An attacker could use this information to launch further attacks against the affected system. | ||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||
CVSS v2 Severity: | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 4.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
| ||||||
Vulnerability Consequences: | Obtain Information | ||||||
References: | Source: CCN Type: SA44206 SAP NetWeaver Portal Path Disclosure Weakness Source: CCN Type: OSVDB ID: 72684 SAP NetWeaver Portal Path Disclosure Weakness Source: CCN Type: BID-47391 SAP Netweaver Multiple Unspecified Cross Site Scripting and Information Disclosure Vulnerabilities Source: XF Type: UNKNOWN netweaver-portal-path-disclosure(66812) Source: CCN Type: SAP Web site SAP Support Note 1513182 | ||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||
BACK |