5.3
CVSSv3

CVE-2019-0338

Published: 14/08/2019 Updated: 26/08/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

During an OData V2/V4 request in SAP Gateway, versions 750, 751, 752, 753, the HTTP Header attributes cache-control and pragma were not properly set, allowing an malicious user to access restricted information, resulting in Information Disclosure.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sap gateway 753

sap gateway 751

sap gateway 752

sap gateway 750