CVE-2014-8312

low
Published 2014-10-16 · Modified 2026-05-06
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

Business Warehouse (BW) in SAP Netweaver AS ABAP 7.31 allows remote authenticated users to obtain sensitive information via a request to the RSDU_CCMS_GET_PROFILE_PARAM RFC function.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://service.sap.com/sap/support/notes/1967780

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://scn.sap.com/docs/DOC-8218

Application impact

VendorProductVersionsFixed
sapnetweaver_abap7.31

References

Verify integrity in audit chain (admin only). AS-IS.