PT-2024-8875 · Sap · Sap Netweaver As Java

Published

2024-11-11

·

Updated

2024-11-12

·

CVE-2024-42372

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: SAP NetWeaver AS Java (affected versions not specified)
Description: The issue is related to a missing authorization check in SAP NetWeaver AS Java, specifically in the System Landscape Directory. This allows an unauthorized user to read and modify some restricted global SLD configurations, resulting in a low impact on the confidentiality and integrity of the application.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-10542
CVE-2024-42372

Affected Products

Sap Netweaver As Java