CVE-2021-27598

Publication date

2021-04-13 18:38:46

Family

sap

State

PUBLISHED

Description

SAP NetWeaver AS JAVA (Customer Usage Provisioning Servlet), versions - 7.31, 7.40, 7.50, allows an attacker to read some statistical data like product version, traffic, timestamp etc. because of missing authorization check in the servlet.