CVE-2024-39598

MEDIUM

SAP CRM WebClient UI Framework - Authenticated Server-Side Request Forgery

Title source: llm
STIX 2.1

Description

SAP CRM (WebClient UI Framework) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in information disclosure. It has no impact on integrity and availability of the application.

References (2)

Core 2
Core References
Permissions Required
https://me.sap.com/notes/3467377

Scores

CVSS v3 5.0
EPSS 0.0044
EPSS Percentile 63.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (14)
sap/customer_relationship_management_s4fnd 102
sap/customer_relationship_management_s4fnd 103
sap/customer_relationship_management_s4fnd 104
sap/customer_relationship_management_s4fnd 105
sap/customer_relationship_management_s4fnd 106
sap/customer_relationship_management_s4fnd 107
sap/customer_relationship_management_s4fnd 108
sap/customer_relationship_management_webclient_ui 701
sap/customer_relationship_management_webclient_ui 731
sap/customer_relationship_management_webclient_ui 746
... and 4 more
Published Jul 09, 2024
Tracked Since Feb 18, 2026