CVE-2023-29111: SAP Application Interface Framework
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
The SAP AIF (ODATA service) - versions 755, 756, discloses more detailed information than is required. An authorized attacker can use the collected information possibly to exploit the component. As a result, an attacker can cause a low impact on the confidentiality of the application.
Affected products
- SAP Application Interface Framework: version 755 only; version 756 only
Published 2023-04-11. Last modified 2026-06-17.