PT-2024-9306 · Sap · Sap Netweaver Administrator

Published

2024-12-02

·

Updated

2024-12-10

·

CVE-2024-54197

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: SAP NetWeaver Administrator (affected versions not specified)
Description: The issue allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests, potentially resulting in Server-Side Request Forgery (SSRF). This could have a low impact on the integrity and confidentiality of data, with no impact on the availability of the application. The vulnerability is related to insufficient server-side request checking.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Weakness Enumeration

Related Identifiers

BDU:2024-10995
CVE-2024-54197

Affected Products

Sap Netweaver Administrator