CVE-2024-41734

Severity
4.3MEDIUM
EPSS
0.4%
top 41.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 13

Description

Due to missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform, an authenticated attacker could call an underlying transaction, which leads to disclosure of user related information. There is no impact on integrity or availability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-45m2-f9mw-223r: Due to missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform, an authenticated attacker could call an underlying tran2024-08-13
CVEList
Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform2024-08-13
CVE-2024-41734 (MEDIUM CVSS 4.3) | Due to missing authorization check | cvebase.io