CVE-2024-44114
LOWSAP NetWeaver Application Server ABAP - Unauthorized Data Exposure via High Privilege Program Execution
Title source: llmDescription
SAP NetWeaver Application Server for ABAP and ABAP Platform allow users with high privileges to execute a program that reveals data over the network. This results in a minimal impact on confidentiality of the application.
References (2)
Core 2
Core References
Permissions Required
https://me.sap.com/notes/3507252
Scores
CVSS v3
2.0
EPSS
0.0009
EPSS Percentile
24.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-863
Status
published
Products (13)
sap/netweaver_application_server_abap
702
sap/netweaver_application_server_abap
731
sap/netweaver_application_server_abap
740
sap/netweaver_application_server_abap
750
sap/netweaver_application_server_abap
751
sap/netweaver_application_server_abap
752
sap/netweaver_application_server_abap
753
sap/netweaver_application_server_abap
754
sap/netweaver_application_server_abap
755
sap/netweaver_application_server_abap
756
... and 3 more
Published
Sep 10, 2024
Tracked Since
Feb 18, 2026