SAP NetWeaver Application Server Java
cpe:2.3:a:sap:application_server_java:*:*:*:*:*:*:*, +5 more
A vulnerability in SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to send a malicious HTTP logon request that manipulates file inclusion parameters. This exploitation enables path traversal and the processing of the included file. Such processing could lead to unauthorized viewing or modification of sensitive information or cause disruption to local system availability.
Exploitation of this vulnerability could result in unauthorized access to sensitive information, unauthorized modification of data, or disruption of local system services.
Users are advised to consult the SAP Security Notes for guidance on applying patches and addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.