VYPR
Medium severity5.3NVD Advisory· Published Aug 14, 2019· Updated Jun 17, 2026

CVE-2019-0338

CVE-2019-0338

Description

During an OData V2/V4 request in SAP Gateway, versions 750, 751, 752, 753, the HTTP Header attributes cache-control and pragma were not properly set, allowing an attacker to access restricted information, resulting in Information Disclosure.

Affected products

6
  • SAP SE/SAP Gatewayv5
    Range: < 750
  • SAP/Gateway5 versions
    cpe:2.3:a:sap:gateway:750:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:sap:gateway:750:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:gateway:751:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:gateway:752:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:gateway:753:*:*:*:*:*:*:*
    • (no CPE)range: 750, 751, 752, 753

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.