7.5

CVE-2015-2816

The XcListener in SAP Afaria 7.0.6001.5 does not properly restrict access, which allows remote attackers to have unspecified impact via a crafted request, aka SAP Security Note 2134905.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Afaria Version 7.0.6001.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.56% 0.833
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

http://packetstormsecurity.com/files/132363/SAP-Afaria-7-Missing-Authorization-Check.html
http://seclists.org/fulldisclosure/2015/Jun/67
http://www.securityfocus.com/archive/1/535830/100/800/threaded
http://www.securityfocus.com/bid/73708
https://erpscan.io/advisories/erpscan-15-009-sap-afaria-7-xclistener-missing-authorization-check/