Medium severity5.3NVD Advisory· Published Aug 14, 2019· Updated Jun 17, 2026
CVE-2019-0338
CVE-2019-0338
Description
During an OData V2/V4 request in SAP Gateway, versions 750, 751, 752, 753, the HTTP Header attributes cache-control and pragma were not properly set, allowing an attacker to access restricted information, resulting in Information Disclosure.
Affected products
6- SAP SE/SAP Gatewayv5Range: < 750
Patches
Vulnerability mechanics
References
2- launchpad.support.sap.comnvdPermissions RequiredVendor Advisory
- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdVendor Advisory
News mentions
0No linked articles in our index yet.