CVE-2024-37180
Severity
5.3MEDIUM
EPSS
0.1%
top 70.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 9
Description
Under certain conditions SAP NetWeaver
Application Server for ABAP and ABAP Platform allows an attacker to access
remote-enabled function module with no further authorization which would
otherwise be restricted, the function can be used to read non-sensitive
information with low impact on confidentiality of the application.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:NExploitability: 2.3 | Impact: 1.4
Affected Packages2 packages
Patches
🔴Vulnerability Details
2CVEList▶
[CVE-2024-37180] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform↗2024-07-09
GHSA▶
GHSA-p594-8qmm-h7mr: Under certain conditions SAP NetWeaver
Application Server for ABAP and ABAP Platform allows an attacker to access
remote-enabled function module with↗2024-07-09