CVE-2024-37180

Severity
5.3MEDIUM
EPSS
0.1%
top 70.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 9

Description

Under certain conditions SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to access remote-enabled function module with no further authorization which would otherwise be restricted, the function can be used to read non-sensitive information with low impact on confidentiality of the application.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:NExploitability: 2.3 | Impact: 1.4

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
CVEList
[CVE-2024-37180] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform2024-07-09
GHSA
GHSA-p594-8qmm-h7mr: Under certain conditions SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to access remote-enabled function module with2024-07-09