Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Obsolete Encryption Algorithm Used in NW AS Java UME User Mapping
Vulnerability Description
The User Management Engine (UME) in NetWeaver Application Server for Java (NW AS Java) utilizes an obsolete cryptographic algorithm for encrypting User Mapping data. This weakness could allow an attacker with high-privileged access to exploit the vulnerability under specific conditions potentially leading to partial disclosure of sensitive information.This has low impact on confidentiality with no impact on integrity and availability of the application.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
Vulnerability Type
不充分的加密强度
Vulnerability Title
SAP NetWeaver 加密问题漏洞
Vulnerability Description
SAP NetWeaver是德国思爱普(SAP)公司的一套面向服务的集成化应用平台。该平台主要为SAP应用程序提供开发和运行环境。 SAP NetWeaver存在加密问题漏洞,该漏洞源于使用过时的加密算法,可能导致高权限攻击者在特定条件下部分泄露敏感信息,对应用程序机密性造成低影响。
CVSS Information
N/A
Vulnerability Type
N/A