CVE-2024-41734

MEDIUM

SAP NetWeaver Application Server ABAP - Authenticated Information Disclosure via Missing Authorization

Title source: llm
STIX 2.1

Description

Due to missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform, an authenticated attacker could call an underlying transaction, which leads to disclosure of user related information. There is no impact on integrity or availability.

References (2)

Core 2
Core References
Permissions Required
https://me.sap.com/notes/3494349

Scores

CVSS v3 4.3
EPSS 0.0028
EPSS Percentile 51.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (15)
sap/netweaver_application_server_abap sap_basis_700
sap/netweaver_application_server_abap sap_basis_701
sap/netweaver_application_server_abap sap_basis_702
sap/netweaver_application_server_abap sap_basis_731
sap/netweaver_application_server_abap sap_basis_740
sap/netweaver_application_server_abap sap_basis_750
sap/netweaver_application_server_abap sap_basis_751
sap/netweaver_application_server_abap sap_basis_752
sap/netweaver_application_server_abap sap_basis_753
sap/netweaver_application_server_abap sap_basis_754
... and 5 more
Published Aug 13, 2024
Tracked Since Feb 18, 2026