7.7
CVE-2024-39598
- EPSS 0.31%
- Veröffentlicht 09.07.2024 04:15:14
- Zuletzt bearbeitet 21.11.2024 09:28:05
- Erkennungen
[Multiple CVEs] Multiple vulnerabilities in SAP CRM (WebClient UI)
SAP CRM (WebClient UI Framework) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in information disclosure. It has no impact on integrity and availability of the application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Customer Relationship Management S4fnd Version 102
SAP ≫ Customer Relationship Management S4fnd Version 103
SAP ≫ Customer Relationship Management S4fnd Version 104
SAP ≫ Customer Relationship Management S4fnd Version 105
SAP ≫ Customer Relationship Management S4fnd Version 106
SAP ≫ Customer Relationship Management S4fnd Version 107
SAP ≫ Customer Relationship Management S4fnd Version 108
SAP ≫ Customer Relationship Management Webclient Ui Version 701
SAP ≫ Customer Relationship Management Webclient Ui Version 731
SAP ≫ Customer Relationship Management Webclient Ui Version 746
SAP ≫ Customer Relationship Management Webclient Ui Version 747
SAP ≫ Customer Relationship Management Webclient Ui Version 748
SAP ≫ Customer Relationship Management Webclient Ui Version 800
SAP ≫ Customer Relationship Management Webclient Ui Version 801
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.224 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.7 | 3.1 | 4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
|
| SAP | 5 | 3.1 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
|
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
https://url.sap/sapsecuritypatchday
https://me.sap.com/notes/3467377