CVE-2024-42371
Multiple vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 5.4EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
10 set 2024Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
The RFC enabled function module allows a low privileged user to delete the workplace favourites of any user. This vulnerability could be utilized to identify usernames and access information about targeted user's workplaces and nodes. There is low impact on integrity and availability of the application.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Produtos afetados
SAP_SE · SAP NetWeaver Application Server for ABAP and ABAP PlatformQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →