GHSA-crm7-ph4v-r8hv
GitHub Security Advisory
⚠ Unreviewed
MODERATE
Has CVE
Advisory Details
Due to missing authentication check in webdynpro application, an unauthorized user in SAP NetWeaver (Guided Procedures) - version 7.50, can gain access to admin view of specific function anonymously. On successful exploitation of vulnerability under specific circumstances, attacker can view user’s email address. There is no integrity/availability impact.
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 8, 2025 6:31 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.