SAP NetWeaver Application Server ABAP
cpe:2.3:a:sap:netweaver_application_server_abap:*:*:*:*:*:*:*
A vulnerability allowing a missing authorization check has been identified in the Virus Scanner Interface of SAP NetWeaver Application Server ABAP. This issue enables an authenticated user with non-administrative privileges to initiate a transaction that accesses, but does not modify, non-sensitive data without additional authorization. The vulnerability does not impact system availability.
Exploitation of this vulnerability allows unauthorized access to non-sensitive data, with no effect on system availability.
Users are advised to review and implement the SAP Security Note associated with this vulnerability. This can be done through the SAP for Me platform, specifically during the monthly SAP Security Patch Day.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.