PT-2019-5669 · Sap · Sap Gateway

Publicado

2019-08-13

·

Atualizado

2019-08-26

·

CVE-2019-0338

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP Gateway versions 750 through 753
Description The issue is related to the improper setting of HTTP Header attributes cache-control and pragma during an OData V2/V4 request, allowing an attacker to access restricted information. This results in information disclosure. The vulnerability is associated with a lack of protection for service data in the SAP Gateway environment, which can be exploited by a remote attacker to disclose protected information due to incorrectly set HTTP headers.
Recommendations For SAP Gateway versions 750 through 753, update the HTTP Header attributes to properly set cache-control and pragma to prevent information disclosure. As a temporary workaround, consider restricting access to sensitive information until the issue is resolved.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-04960
CVE-2019-0338

Produtos afetados

Sap Gateway