Description
Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper security requirements for the content of the newly defined security answer. This can be leveraged by an attacker to cause profound impact on confidentiality and low impact on both integrity and availability.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-25091 | Self-Registration and Modify your own profile in User Admin Application of NetWeaver AS Java does not enforce proper security requirements for the content of the newly defined security answer. This can be leveraged by an attacker to cause profound impact on confidentiality and low impact on both integrity and availability. |
References
History
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-08-27T15:48:33.372Z
Reserved: 2024-02-27T06:26:16.787Z
Link: CVE-2024-27899
Updated: 2024-08-02T00:41:55.550Z
Status : Deferred
Published: 2024-04-09T01:15:48.777
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-27899
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD