CVE-2024-22131
CRITICALSAP ABAP Platform - Authenticated Remote Code Execution via Vulnerable Interface
Title source: llmDescription
In SAP ABA (Application Basis) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75I, an attacker authenticated as a user with a remote execution authorization can use a vulnerable interface. This allows the attacker to use the interface to invoke an application function to perform actions which they would not normally be permitted to perform. Depending on the function executed, the attack can read or modify any user/business data and can make the entire system unavailable.
References (2)
Core 2
Core References
Permissions Required
https://me.sap.com/notes/3420923
Scores
CVSS v3
9.1
EPSS
0.0307
EPSS Percentile
86.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-94
Status
published
Products (10)
sap/abap_platform
75c
sap/abap_platform
75i
sap/abap_platform
700
sap/abap_platform
701
sap/abap_platform
702
sap/abap_platform
731
sap/abap_platform
740
sap/abap_platform
750
sap/abap_platform
751
sap/abap_platform
752
Published
Feb 13, 2024
Tracked Since
Feb 18, 2026