SAP NetWeaver AS Java (CAF - Guided Procedures) allows an unauthenticated user to access non-sensitive information about the server which would otherwise be restricted causing low impact on confidentiality of the application.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://me.sap.com/notes/3425571 | permissions required |
https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html | vendor advisory |