5.3

CVE-2024-37180

[CVE-2024-37180] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform

Under certain conditions SAP NetWeaver
Application Server for ABAP and ABAP Platform allows an attacker to access
remote-enabled function module with no further authorization which would
otherwise be restricted, the function can be used to read non-sensitive
information with low impact on confidentiality of the application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Sap Basis Version 700
SAP ≫ Sap Basis Version 701
SAP ≫ Sap Basis Version 702
SAP ≫ Sap Basis Version 731
SAP ≫ Sap Basis Version 740
SAP ≫ Sap Basis Version 750
SAP ≫ Sap Basis Version 751
SAP ≫ Sap Basis Version 752
SAP ≫ Sap Basis Version 753
SAP ≫ Sap Basis Version 754
SAP ≫ Sap Basis Version 755
SAP ≫ Sap Basis Version 756
SAP ≫ Sap Basis Version 757
SAP ≫ Sap Basis Version 758
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.216
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
SAP 4.1 2.3 1.4
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://url.sap/sapsecuritypatchday
Patch
https://me.sap.com/notes/3454858
Permissions Required