SAP NetWeaver Developer Studio (NWDS) - version 7.50, is based on Eclipse, which contains the logging framework log4j in version 1.x. The applications confidentiality and integrity could have a low impact due to the vulnerabilities associated with version 1.x.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Netweaver_developer_studio | Sap | 7.50 (including) | 7.50 (including) |