PT-2024-9678 · Sap · Sap Netweaver Application Server Abap

Published

2024-12-02

·

Updated

2024-12-10

·

CVE-2024-54198

CVSS v3.1

8.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP NetWeaver Application Server ABAP (affected versions not specified)
Description The issue allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, potentially exposing credentials for a remote service. These credentials can then be further exploited to completely compromise the remote service, impacting the confidentiality, integrity, and availability of the application. The vulnerability is related to insufficient control of dynamically determined variables in the Remote Function Call (RFC) interface.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2024-11390
CVE-2024-54198

Affected Products

Sap Netweaver Application Server Abap