The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to identify the legitimate user ids. This will have an impact on confidentiality but there is no other impact on integrity or availability.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: sap

Published: 2023-11-14T01:02:56.929Z

Updated: 2023-11-14T01:02:56.929Z

Reserved: 2023-09-11T07:15:13.775Z


Link: CVE-2023-42480

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-11-14T01:15:07.907

Modified: 2023-11-20T19:59:14.070


Link: CVE-2023-42480

JSON object: View

cve-icon Redhat Information

No data.

CWE