ZeroHour

CVE-2021-27598

CVSS 3.1
5.3 medium
EPSS
<1%p48
Published
()
Modified
Description

SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like product version, traffic, timestamp etc. because of missing authorization check in the servlet.

Vendors
sap
Products
netweaver application server java
Weakness
CWE-284, CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.