CVE Vulnerabilities

CVE-2024-45283

Plaintext Storage of a Password

Published: Sep 10, 2024 | Modified: Sep 10, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

SAP NetWeaver AS for Java allows an authorized attacker to obtain sensitive information. The attacker could obtain the username and password when creating an RFC destination. After successful exploitation, an attacker can read the sensitive information but cannot modify or delete the data.

Weakness

Storing a password in plaintext may result in a system compromise.

Potential Mitigations

References