SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, which reveals sensitive system information that would otherwise be restricted to highly privileged users because of missing authorization, resulting in Information Disclosure.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/2971954 | Permissions Required Vendor Advisory |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=562725571 | Vendor Advisory |
https://launchpad.support.sap.com/#/notes/2971954 | Permissions Required Vendor Advisory |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=562725571 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:20
Type | Values Removed | Values Added |
---|---|---|
References | () https://launchpad.support.sap.com/#/notes/2971954 - Permissions Required, Vendor Advisory | |
References | () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=562725571 - Vendor Advisory |
Information
Published : 2020-11-10 17:15
Updated : 2024-11-21 05:20
NVD link : CVE-2020-26818
Mitre link : CVE-2020-26818
CVE.ORG link : CVE-2020-26818
JSON object : View
Products Affected
sap
- netweaver_application_server_abap
CWE
CWE-862
Missing Authorization