PT-2019-5669 · Sap · Sap Gateway

Published

2019-08-13

·

Updated

2019-08-26

·

CVE-2019-0338

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP Gateway versions 750 through 753
Description The issue is related to the improper setting of HTTP Header attributes cache-control and pragma during an OData V2/V4 request, allowing an attacker to access restricted information. This results in information disclosure. The vulnerability is associated with a lack of protection for service data in the SAP Gateway environment, which can be exploited by a remote attacker to disclose protected information due to incorrectly set HTTP headers.
Recommendations For SAP Gateway versions 750 through 753, update the HTTP Header attributes to properly set cache-control and pragma to prevent information disclosure. As a temporary workaround, consider restricting access to sensitive information until the issue is resolved.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04960
CVE-2019-0338

Affected Products

Sap Gateway