Overview
- Description
- During an OData V2/V4 request in SAP Gateway, versions 750, 751, 752, 753, the HTTP Header attributes cache-control and pragma were not properly set, allowing an attacker to access restricted information, resulting in Information Disclosure.
- Source
- cna@sap.com
- NVD status
- Analyzed
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 5.3
- Impact score
- 1.4
- Exploitability score
- 3.9
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-200
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:sap:gateway:750:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EE48FA0B-81A3-4266-B82F-F82E7631C7AA" }, { "criteria": "cpe:2.3:a:sap:gateway:751:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7290C61F-19FF-42CD-8109-56D5BA1351EE" }, { "criteria": "cpe:2.3:a:sap:gateway:752:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D7F41777-93EE-4E71-A268-74041EFAEF64" }, { "criteria": "cpe:2.3:a:sap:gateway:753:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BFCE57CC-9214-495A-B03A-04EAA308D589" } ], "operator": "OR" } ] } ]