SAP NetWeaver Application Server ABAP and ABAP Platform Vulnerability Could Lead to Disclosure of User Related Information
CVE-2024-41734
4.3MEDIUM
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 13 August 2024
Summary
Due to missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform, an authenticated attacker could call an underlying transaction, which leads to disclosure of user related information. There is no impact on integrity or availability.
Affected Version(s)
SAP NetWeaver Application Server ABAP and ABAP Platform SAP_BASIS 700
SAP NetWeaver Application Server ABAP and ABAP Platform SAP_BASIS 701
SAP NetWeaver Application Server ABAP and ABAP Platform SAP_BASIS 702
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved