5.4
CVE-2024-41732
- EPSS 0.09%
- Published 13.08.2024 04:15:08
- Last modified 11.09.2024 17:52:39
- Source cna@sap.com
- Teams watchlist Login
- Open Login
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that could bypass allowlist controls. Depending on the web applications provided by this server, the attacker might inject CSS code or links into the web application that could allow the attacker to read or modify information. There is no impact on availability of application.
Data is provided by the National Vulnerability Database (NVD)
SAP ≫ Netweaver Application Server Abap Version755
SAP ≫ Netweaver Application Server Abap Version756
SAP ≫ Netweaver Application Server Abap Version757
SAP ≫ Netweaver Application Server Abap Version758
SAP ≫ Netweaver Application Server Abap Versionsap_basis_700
SAP ≫ Netweaver Application Server Abap Versionsap_basis_701
SAP ≫ Netweaver Application Server Abap Versionsap_basis_702
SAP ≫ Netweaver Application Server Abap Versionsap_basis_731
SAP ≫ Netweaver Application Server Abap Versionsap_basis_912
SAP ≫ Netweaver Application Server Abap Versionsap_ui_754
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.09% | 0.269 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
|
cna@sap.com | 4.7 | 1.6 | 2.7 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.