This security bulletin contains one low risk vulnerability.
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the webdynpro application in SAP NetWeaver Guided Procedures. A remote attacker can bypass implemented security restrictions and view user’s email address.Mitigation
Install updates from vendor's website.Vulnerable software versions
SAP NetWeaver: 7.50Fixed software versions
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?