CVE-2019-0338
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
14/08/2019
Last modified:
26/08/2019
Description
During an OData V2/V4 request in SAP Gateway, versions 750, 751, 752, 753, the HTTP Header attributes cache-control and pragma were not properly set, allowing an attacker to access restricted information, resulting in Information Disclosure.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sap:gateway:750:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:gateway:751:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:gateway:752:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:gateway:753:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



