SAP NetWeaver allows an authenticated non-administrative user to call the remote-enabled function module which could grants access to non-sensitive information about the SAP system and OS without requiring any specific knowledge or controlled conditions. This leads to a low impact on confidentiality with no effect on integrity or availability of the application.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Netweaver | Sap | 700 (including) | 700 (including) |
| Netweaver | Sap | 701 (including) | 701 (including) |
| Netweaver | Sap | 702 (including) | 702 (including) |
| Netweaver | Sap | 710 (including) | 710 (including) |
| Netweaver | Sap | 731 (including) | 731 (including) |
| Netweaver | Sap | 740 (including) | 740 (including) |
| Netweaver | Sap | 750 (including) | 750 (including) |
| Netweaver | Sap | 751 (including) | 751 (including) |
| Netweaver | Sap | 752 (including) | 752 (including) |
| Netweaver | Sap | 753 (including) | 753 (including) |
| Netweaver | Sap | 754 (including) | 754 (including) |
| Netweaver | Sap | 755 (including) | 755 (including) |
| Netweaver | Sap | 756 (including) | 756 (including) |
| Netweaver | Sap | 757 (including) | 757 (including) |
| Netweaver | Sap | 758 (including) | 758 (including) |
| Netweaver | Sap | 816 (including) | 816 (including) |
| Netweaver | Sap | 914 (including) | 914 (including) |
| Netweaver | Sap | 916 (including) | 916 (including) |