Home
MEDIUM: 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NDefault status
unaffected
SAP_GWFND 750
affected
751
affected
752
affected
753
affected
754
affected
755
affected
756
affected
757
affected
758
affected
SAP_BASIS 795
affected
Description
The SAP Gateway allows attackers to inject content into error messages, potentially leading to disclosure of request artefacts (e.g., regex patterns) and revealing underlying URI parsing logic. Leading to low impact on confidentiality. Integrity and availability are unaffected.
Problem types
CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere
Product status
SAP_GWFND 750
751
752
753
754
755
756
757
758
SAP_BASIS 795