SAP NetWeaver AS Java
cpe:2.3:a:sap:netweaver_application_server_java:*:*:*:*:*:*:*, +2 more
A vulnerability exists in the SAP NetWeaver AS Java application that utilizes Adobe Document Service, due to an outdated version of OpenSSL. This vulnerability allows users with high system privileges to exploit known issues in the old OpenSSL library, potentially leading to unauthorized access and modification of system information. While the vulnerability has a low impact on confidentiality and integrity, it does not affect availability.
Exploitation of this vulnerability could result in unauthorized access to and modification of system information.
Users are advised to review and implement the latest SAP Security Notes. Security fixes for SAP NetWeaver based products are delivered with the support packages. For information on the latest SAP Security Patch Day, refer to the SAP Security Patch Day Bulletin Archive.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.