SAP NetWeaver AS ABAP (Web Dynpro), versions - 731, 740, 750, 751, 752, 753, 754, 755, 782, allows an authenticated user to access Web Dynpro components, which reveals sensitive system information that would otherwise be restricted to highly privileged users because of missing authorization, resulting in Information Disclosure.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/2971954 | Permissions Required Vendor Advisory |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=562725571 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-11-10 09:15
Updated : 2022-10-05 07:16
NVD link : CVE-2020-26818
Mitre link : CVE-2020-26818
JSON object : View
CWE
CWE-862
Missing Authorization
Products Affected
sap
- netweaver_application_server_abap