漏洞标题
SAP NetWeaver应用服务器Java的信息披露漏洞
漏洞描述信息
SAP NetWeaver Application Server Java 存在信息泄露漏洞。攻击者可以访问一个能够披露已部署服务器组件信息的端点,包括这些组件的 XML 定义。这些信息应仅限于客户管理员访问,即使他们可能并不需要。这些 XML 文件并非完全是 SAP 内部的,因为它们会随服务器一起部署。在这种情况下,可能会泄露敏感信息,但不会影响其完整性和可用性。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
漏洞类别
信息暴露
漏洞标题
Information Disclosure vulnerability in SAP NetWeaver Application Server Java
漏洞描述信息
SAP NetWeaver Application Server Java allows an attacker to access an endpoint that can disclose information about deployed server components, including their XML definitions. This information should ideally be restricted to customer administrators, even though they may not need it. These XML files are not entirely SAP-internal as they are deployed with the server. In such a scenario, sensitive information could be exposed without compromising its integrity or availability.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
漏洞类别
授权机制不正确