PT-2024-1546 · Sap · Sap Web Dispatcher+1

Published

2024-01-08

·

Updated

2024-01-22

·

CVE-2024-22124

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP Internet Communication Manager (ICM) or SAP Web Dispatcher versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, KRNL64NUC 7.22, KRNL64NUC 7.22 EXT, WEBDISP 7.22 EXT, WEBDISP 7.53, WEBDISP 7.54
Description The issue is related to the lack of proper input validation when requesting an external authentication server, which could allow an attacker to access restricted information, causing a high impact on confidentiality. This can be achieved by sending a specially crafted request.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-01081
CVE-2024-22124

Affected Products

Internet Communication Manager
Sap Web Dispatcher