Due to improper input controls In SAP NetWeaver AS for...
High severity
Unreviewed
Published
Mar 14, 2023
to the GitHub Advisory Database
•
Updated Mar 30, 2023
Description
Published by the National Vulnerability Database
Mar 14, 2023
Published to the GitHub Advisory Database
Mar 14, 2023
Last updated
Mar 30, 2023
Due to improper input controls In SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 791, an attacker authenticated as a non-administrative user can craft a request which will trigger the application server to send a request to an arbitrary URL which can reveal, modify or make unavailable non-sensitive information, leading to low impact on Confidentiality, Integrity and Availability.
References