When user with insufficient privileges tries to access any application in SAP NetWeaver Administrator (Administrator applications), version - 7.50, no security audit log is created. Therefore, security audit log Integrity is impacted.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NSap Netweaver Application Server Java
APPSap7.50
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2020-6287CRITICAL10.0⚠ KEVPL ✓same product
SAP NetWeaver AS Java — brak uwierzytelnienia w LM Configuration Wizard
CVE-2010-5326CRITICAL10.0⚠ KEVPL ✓same product
SAP NetWeaver AS Java — RCE przez Invoker Servlet bez uwierzytelnienia
CVE-2016-2386CRITICAL9.8⚠ KEVPL ✓same product
SQL Injection w serwerze UDDI SAP NetWeaver J2EE Engine 7.40
CVE-2024-22127CRITICAL9.1PL ✓same product
SAP NetWeaver AS Java – command injection przez upload pliku w Log Viewer
CVE-2023-40309CRITICAL9.8PL ✓same product
SAP CommonCryptoLib — brak weryfikacji autoryzacji, privilege escalation