PT-2024-4514 · Sap · Sap Netweaver As Java
Published
2024-02-12
·
Updated
2024-10-16
·
CVE-2024-24743
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
SAP NetWeaver AS Java versions 7.50
Description:
The issue is related to the incorrect restriction of XML links to external objects in the Guided Procedures component of SAP NetWeaver AS for Java. This can be exploited by a remote attacker using a specially crafted XML file to gain unauthorized access to confidential information. The attacker can submit a malicious request with the crafted XML file over the network, allowing access to sensitive files and data, though not modification. There are limits in place to prevent impact on availability.
Recommendations:
For version 7.50, consider restricting access to the Guided Procedures component until a fix is available. As a temporary workaround, avoid using the
XML file parsing functionality in the affected component to minimize the risk of exploitation.Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Netweaver As Java