- Description
- During an OData V2/V4 request in SAP Gateway, versions 750, 751, 752, 753, the HTTP Header attributes cache-control and pragma were not properly set, allowing an attacker to access restricted information, resulting in Information Disclosure.
- Source
- cna@sap.com
- NVD status
- Analyzed
CVSS 3.0
- Type
- Primary
- Base score
- 5.3
- Impact score
- 1.4
- Exploitability score
- 3.9
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
- nvd@nist.gov
- CWE-200
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sap:gateway:750:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EE48FA0B-81A3-4266-B82F-F82E7631C7AA"
},
{
"criteria": "cpe:2.3:a:sap:gateway:751:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7290C61F-19FF-42CD-8109-56D5BA1351EE"
},
{
"criteria": "cpe:2.3:a:sap:gateway:752:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D7F41777-93EE-4E71-A268-74041EFAEF64"
},
{
"criteria": "cpe:2.3:a:sap:gateway:753:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BFCE57CC-9214-495A-B03A-04EAA308D589"
}
],
"operator": "OR"
}
]
}
]