Security Advisory

CVE-2017-5372

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-01-23 21:00:00
Last updated 2024-08-05 14:55:35
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The function msp (aka MSPRuntimeInterface) in the P4 SERVERCORE component in SAP AS JAVA allows remote attackers to obtain sensitive system information by leveraging a missing authorization check for the (1) getInformation, (2) getParameters, (3) getServiceInfo, (4) getStatistic, or (5) getClientStatistic function, aka SAP Security Note 2331908.