SAP CRM (WebClient UI Framework) allows an
authenticated attacker to enumerate accessible HTTP endpoints in the internal
network by specially crafting HTTP requests. On successful exploitation this
can result in information disclosure. It has no impact on integrity and
availability of the application.
References
Link | Resource |
---|---|
https://me.sap.com/notes/3467377 | Permissions Required |
https://url.sap/sapsecuritypatchday | Vendor Advisory |
https://me.sap.com/notes/3467377 | Permissions Required |
https://url.sap/sapsecuritypatchday | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-07-09 04:15
Updated : 2024-11-21 09:28
NVD link : CVE-2024-39598
Mitre link : CVE-2024-39598
CVE.ORG link : CVE-2024-39598
JSON object : View
Products Affected
sap
- customer_relationship_management_s4fnd
- customer_relationship_management_webclient_ui
CWE
CWE-918
Server-Side Request Forgery (SSRF)