Due to missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform, an authenticated attacker could call an underlying transaction, which leads to disclosure of user related information. There is no impact on integrity or availability.
References
Link | Resource |
---|---|
https://me.sap.com/notes/3494349 | Permissions Required |
https://url.sap/sapsecuritypatchday | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-08-13 05:15
Updated : 2024-09-12 13:28
NVD link : CVE-2024-41734
Mitre link : CVE-2024-41734
CVE.ORG link : CVE-2024-41734
JSON object : View
Products Affected
sap
- netweaver_application_server_abap
CWE
CWE-862
Missing Authorization