Vulnerability CVE-2024-45283


Published: 2024-09-10

Description:
SAP NetWeaver AS for Java allows an authorized attacker to obtain sensitive information. The attacker could obtain the username and password when creating an RFC destination. After successful exploitation, an attacker can read the sensitive information but cannot modify or delete the data.

Type:

CWE-256

(Plaintext Storage of a Password)

 References:
https://me.sap.com/notes/3477359
https://url.sap/sapsecuritypatchday

Copyright 2024, cxsecurity.com

 

Back to Top