PT-2024-31536 · Sap · Sap Netweaver As Java

Published

2024-09-09

·

Updated

2024-09-10

·

CVE-2024-45283

CVSS v3.1

6.0

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver AS for Java (affected versions not specified)
Description The issue allows an authorized attacker to obtain sensitive information. The attacker could obtain the username and password when creating an RFC destination. After successful exploitation, an attacker can read the sensitive information but cannot modify or delete the data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12960
CVE-2024-45283

Affected Products

Sap Netweaver As Java