CVE-2024-22131

CRITICAL

SAP ABAP Platform - Authenticated Remote Code Execution via Vulnerable Interface

Title source: llm
STIX 2.1

Description

In SAP ABA (Application Basis) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75I, an attacker authenticated as a user with a remote execution authorization can use a vulnerable interface. This allows the attacker to use the interface to invoke an application function to perform actions which they would not normally be permitted to perform.  Depending on the function executed, the attack can read or modify any user/business data and can make the entire system unavailable.

References (2)

Core 2

Scores

CVSS v3 9.1
EPSS 0.0307
EPSS Percentile 86.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (10)
sap/abap_platform 75c
sap/abap_platform 75i
sap/abap_platform 700
sap/abap_platform 701
sap/abap_platform 702
sap/abap_platform 731
sap/abap_platform 740
sap/abap_platform 750
sap/abap_platform 751
sap/abap_platform 752
Published Feb 13, 2024
Tracked Since Feb 18, 2026