Description
SAP NetWeaver AS JAVA (LM Configuration Wizard) does not perform an authentication check which allows an attacker to execute configuration tasks to perform critical actions against the SAP Java system.
Remediation
Install SAP security patches #2934135, #2939665.
References
Related Vulnerabilities
Drupal CVE-2018-14773 Vulnerability (CVE-2018-14773)
Oracle Database Server CVE-2024-20995 Vulnerability (CVE-2024-20995)
Jenkins Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-3666)
Oracle JRE CVE-2013-2440 Vulnerability (CVE-2013-2440)
Oracle HTTP Server Improper Encoding or Escaping of Output Vulnerability (CVE-2022-25235)