PT-2024-8162 · Sap · Sap Web Dispatcher
Published
2024-11-11
·
Updated
2024-12-11
·
CVE-2024-47590
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
SAP Web Dispatcher versions prior to the November 2024 Patch Day
Description:
An unauthenticated attacker can create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link, input data will be used by the web site page generation to create content which when executed in the victim's browser (XXS) or transmitted to another server (SSRF) gives the attacker the ability to execute arbitrary code on the server fully compromising confidentiality, integrity and availability. The vulnerability is actively exploited in the wild.
Recommendations:
As a temporary workaround, consider disabling the web site page generation feature until a patch is available.
Apply the November 2024 Patch Day updates to SAP Web Dispatcher to resolve the issue.
Restrict access to the SAP Web Dispatcher until the patch is applied to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Web Dispatcher