Vulnerability Name: | CVE-2014-3133 (CCN-92872) | ||||||||
Assigned: | 2014-04-28 | ||||||||
Published: | 2014-04-28 | ||||||||
Updated: | 2014-05-10 | ||||||||
Summary: | SAP Netweaver Java Application Server does not properly restrict access, which allows remote attackers to obtain the list of SAP systems registered on an SLD via an unspecified webdynpro, related to SystemSelection. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-3133 Source: CONFIRM Type: UNKNOWN http://scn.sap.com/docs/DOC-8218 Source: CCN Type: Full Disclosure Mailing List: Mon 28 Apr 2014 [Onapsis Security Advisory 2014-008] SAP NW Portal WD Information Disclosure Source: FULLDISC Type: UNKNOWN 20140428 [Onapsis Security Advisory 2014-008] SAP NW Portal WD Information Disclosure Source: MISC Type: UNKNOWN http://www.onapsis.com/resources/get.php?resid=adv_onapsis-2014-008 Source: BID Type: UNKNOWN 67104 Source: CCN Type: BID-67104 SAP NetWeaver Portal WD Information Disclosure Vulnerability Source: XF Type: UNKNOWN netweaver-portal-wd-info-disc(92872) Source: CCN Type: SAP Web site SAP Note 1922547 Source: CONFIRM Type: UNKNOWN https://service.sap.com/sap/support/notes/1922547 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |