PT-2024-7628 · Sap · Sap Netweaver Application Server Abap+1

Published

2024-08-12

·

Updated

2024-09-12

·

CVE-2024-41734

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP NetWeaver Application Server ABAP and ABAP Platform (affected versions not specified)
Description The issue is related to a missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform. This allows an authenticated attacker to call an underlying transaction, leading to the disclosure of user-related information. There is no impact on integrity or availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-09069
CVE-2024-41734

Affected Products

Abap Platform
Sap Netweaver Application Server Abap