CVE-2024-42372

MEDIUM

SAP NetWeaver AS Java - Info Disclosure

Title source: llm
STIX 2.1

Description

Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthorized user can read and modify some restricted global SLD configurations causing low impact on confidentiality and integrity of the application.

References (2)

Core 2
Core References

Scores

CVSS v3 6.5
EPSS 0.0012
EPSS Percentile 30.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (1)
SAP_SE/SAP NetWeaver AS Java (System Landscape Directory) LM-SLD 7.5
Published Nov 12, 2024
Tracked Since Feb 18, 2026