SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the existence of a specified user, potentially revealing sensitive information. This issue does not enable data modification and has no impact on server availability.
History

Tue, 11 Feb 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Feb 2025 01:00:00 +0000

Type Values Removed Values Added
Description SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respond differently based on the existence of a specified user, potentially revealing sensitive information. This issue does not enable data modification and has no impact on server availability.
Title Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP
Weaknesses CWE-204
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2025-02-11T16:00:41.684Z

Reserved: 2025-01-13T11:13:59.547Z

Link: CVE-2025-23193

cve-icon Vulnrichment

Updated: 2025-02-11T16:00:36.923Z

cve-icon NVD

Status : Received

Published: 2025-02-11T01:15:10.700

Modified: 2025-02-11T01:15:10.700

Link: CVE-2025-23193

cve-icon Redhat

No data.