CVE-2023-24526
Summary
| CVE | CVE-2023-24526 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-14 05:15:00 UTC |
| Updated | 2023-04-11 22:15:00 UTC |
| Description | SAP NetWeaver Application Server Java for Classload Service - version 7.50, does not perform any authentication checks for functionalities that require user identity, resulting in escalation of privileges. This failure has a low impact on confidentiality of the data such that an unassigned user can read non-sensitive server data. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 87538 SAP NetWeaver AS for Java Multiple Vulnerabilities