Vulnerability CVE-2024-27899


Published: 2024-04-09

Description:
Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper security requirements for the content of the newly defined security answer. This can be leveraged by an attacker to cause profound impact on confidentiality and low impact on both integrity and availability.

Type:

CWE-640

(Weak Password Recovery Mechanism for Forgotten Password)

 References:
https://me.sap.com/notes/3434839
https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364

Copyright 2024, cxsecurity.com

 

Back to Top