Home
MEDIUM: 5.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:NDefault status
unaffected
SAP_BASIS 700
affected
SAP_BASIS 701
affected
SAP_BASIS 702
affected
SAP_BASIS 731
affected
SAP_BASIS 740
affected
SAP_BASIS 750
affected
SAP_BASIS 751
affected
SAP_BASIS 752
affected
SAP_BASIS 753
affected
SAP_BASIS 754
affected
SAP_BASIS 755
affected
SAP_BASIS 756
affected
SAP_BASIS 757
affected
SAP_BASIS 758
affected
Description
WebFlow Services of SAP Business Workflow allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in information disclosure. It has no impact on integrity and availability of the application.
Problem types
CWE-918: Server-Side Request Forgery
Product status
SAP_BASIS 700
SAP_BASIS 701
SAP_BASIS 702
SAP_BASIS 731
SAP_BASIS 740
SAP_BASIS 750
SAP_BASIS 751
SAP_BASIS 752
SAP_BASIS 753
SAP_BASIS 754
SAP_BASIS 755
SAP_BASIS 756
SAP_BASIS 757
SAP_BASIS 758