CVE-2024-44117
Multiple vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.4EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
10 Sep 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The RFC enabled function module allows a low privileged user to perform various actions, such as modifying the URLs of any user's favourite nodes and workbook ID. There is low impact on integrity and availability of the application.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Affected products
SAP_SE · SAP NetWeaver Application Server for ABAP and ABAP PlatformWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →