CVE-2017-5372

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
23/01/2017
Last modified:
20/04/2025

Description

The function msp (aka MSPRuntimeInterface) in the P4 SERVERCORE component in SAP AS JAVA allows remote attackers to obtain sensitive system information by leveraging a missing authorization check for the (1) getInformation, (2) getParameters, (3) getServiceInfo, (4) getStatistic, or (5) getClientStatistic function, aka SAP Security Note 2331908.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:netweaver:*:*:*:*:*:*:*:*