Low-privilege User Can Perform Denial of Service and Data Tampering Attacks on SAP GUI
CVE-2024-45285
5.4MEDIUM
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 10 September 2024
What is CVE-2024-45285?
The RFC enabled function module allows a low privileged user to perform denial of service on any user and also change or delete favourite nodes. By sending a crafted packet in the function module targeting specific parameters, the specific targeted user will no longer have access to any functionality of SAP GUI. There is low impact on integrity and availability of the application.
Affected Version(s)
SAP NetWeaver Application Server for ABAP and ABAP Platform 700
SAP NetWeaver Application Server for ABAP and ABAP Platform 701
SAP NetWeaver Application Server for ABAP and ABAP Platform 702