← Back

CVE-2024-41734

nvd nist
Published: Aug 13, 2024Modified: Sep 12, 2024

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

Due to missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform, an authenticated attacker could call an underlying transaction, which leads to disclosure of user related information. There is no impact on integrity or availability.

Affected (15)

1 product
Netweaver Application Server Abap
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version sap_basis_700
Version sap_basis_701
Version sap_basis_702
Version sap_basis_731
Version sap_basis_740
Version sap_basis_750
Version sap_basis_751
Version sap_basis_752
Version sap_basis_753
Version sap_basis_754
Version sap_basis_755
Version sap_basis_756
Version sap_basis_757
Version sap_basis_758
Version sap_basis_912

References (2)

Source: cna@sap.com
Permissions Required
Source: cna@sap.com
Vendor Advisory

Timeline

No history available yet.