CVE

Id
102192  
CVE No.
CVE-2017-5372  
Status
Candidate  
Description
The function msp (aka MSPRuntimeInterface) in the P4 SERVERCORE component in SAP AS JAVA allows remote attackers to obtain sensitive system information by leveraging a missing authorization check for the (1) getInformation, (2) getParameters, (3) getServiceInfo, (4) getStatistic, or (5) getClientStatistic function, aka SAP Security Note 2331908.  
Phase
Assigned (20170113)  
Votes
None (candidate not yet proposed)  
Comments