VDB
GCVE-110-NCSC-2024-378
GCVE-110-NCSC-2024-378
Advisory PublishedCVSS 5.9/10
Exposure of Private Personal Information to an Unauthorized Actor
Weaknesses (CWE)
CWE-325Missing Cryptographic StepCWE-862Missing AuthorizationCWE-359Exposure of Private Personal Information to an Unauthorized ActorCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-863Incorrect AuthorizationCWE-213Exposure of Sensitive Information Due to Incompatible PoliciesCWE-426Untrusted Search PathCWE-256Plaintext Storage of a Password
Risk Scores
CVSS 3.1
5.9/10
Medium · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| sap_se | sap_netweaver_application_server_for_abap__crm_blueprint_application_builder_panel_ | — | — |
| sap_se | sap_businessobjects_business_intelligence_platform | — | — |
| sap | netweaver_enterprise_portal | — | — |
| sap_se | sap_production_and_revenue_accounting__tobin_interface_ | — | — |
| sap | student_life_cycle_management | — | — |
| sap | businessobjects_business_intelligence_platform | — | — |
| sap_se | sap_business_warehouse__bex_analyzer_ | — | — |
| sap | netweaver_as_for_java | — | — |
| sap_se | sap_student_life_cycle_management__slcm_ | — | — |
| sap_se | sap_for_oil___gas | — | — |
| sap_se | sap_netweaver_application_server_for_abap_and_abap_platform | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap | oil_\%\/_gas | — | — |
| sap_se | sap_s_4hana_eprocurement | — | — |
| sap_se | sap_netweaver_enterprise_portal | — | — |
| sap_se | sap_netweaver_as_for_java__destination_service_ | — | — |
| sap | sap | — | — |
| sap_se | sap_netweaver_as_java__logon_application_ | — | — |
| sap_se | sap_s_4_hana__statutory_reports_ | — | — |
| sap_se | sap_netweaver_bw__bex_analyzer_ | — | — |
| sap | commerce_cloud | — | — |
Aliases
Browse GCVE Records
76,019 records in the GCVE database · Updated August 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.