SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like product version, traffic, timestamp etc. because of missing authorization check in the servlet.
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://launchpad.support.sap.com/#/notes/3027937 | permissions required |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=573801649 | vendor advisory |