Information Disclosure Vulnerability in SAP NetWeaver Application Server Java (Logon Application)
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.3%
exploitation probability
0.3%top 77% of all CVEs
observed exploitation
nono source reports it
SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality in order to identify the legitimate user IDs. This has an impact on confidentiality but not on integrity or availability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
SAP_SE · SAP NetWeaver Application Server Java (Logon Application)