SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to gain unauthorized access to system information. By using a specific URL parameter, an unauthenticated attacker could retrieve details such as system configuration. This has a limited impact on the confidentiality of the application and may be leveraged to facilitate further attacks or exploits.
| Software | From | Fixed in |
|---|---|---|
| sap / sap_basis | 700 | 700.x |
| sap / sap_basis | 701 | 701.x |
| sap / sap_basis | 702 | 702.x |
| sap / sap_basis | 731 | 731.x |
| sap / sap_basis | 740 | 740.x |
| sap / sap_basis | 750 | 750.x |
| sap / sap_basis | 751 | 751.x |
| sap / sap_basis | 752 | 752.x |
| sap / sap_basis | 753 | 753.x |
| sap / sap_basis | 754 | 754.x |
| sap / sap_basis | 755 | 755.x |
| sap / sap_basis | 756 | 756.x |
| sap / sap_basis | 757 | 757.x |