Vulnerabilities > CVE-2023-41367 - Unspecified vulnerability in SAP Netweaver 7.50
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) - version 7.50, can gain access to admin view of specific function anonymously. On successful exploitation of vulnerability under specific circumstances, attacker can view user’s email address. There is no integrity/availability impact.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |