CVE-2024-41732

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that could bypass allowlist controls. Depending on the web applications provided by this server, the attacker might inject CSS code or links into the web application that could allow the attacker to read or modify information. There is no impact on availability of application.
References
Link Resource
https://me.sap.com/notes/3468102 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:netweaver_application_server_abap:755:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:756:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:757:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:758:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:sap_basis_700:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:sap_basis_701:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:sap_basis_702:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:sap_basis_731:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:sap_basis_912:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:sap_ui_754:*:*:*:*:*:*:*

History

11 Sep 2024, 17:52

Type Values Removed Values Added
First Time Sap netweaver Application Server Abap
Sap
CPE cpe:2.3:a:sap:netweaver_application_server_abap:755:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:757:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:sap_basis_731:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:758:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:sap_basis_702:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:756:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:sap_ui_754:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:sap_basis_912:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:sap_basis_700:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_application_server_abap:sap_basis_701:*:*:*:*:*:*:*
Summary
  • (es) SAP NetWeaver Application Server ABAP permite a un atacante no autenticado crear un enlace URL que podría eludir los controles de la lista de permitidos. Dependiendo de las aplicaciones web proporcionadas por este servidor, el atacante podría inyectar código CSS o enlaces en la aplicación web que podrían permitirle leer o modificar información. No hay ningún impacto en la disponibilidad de la aplicación.
References () https://me.sap.com/notes/3468102 - () https://me.sap.com/notes/3468102 - Permissions Required
References () https://url.sap/sapsecuritypatchday - () https://url.sap/sapsecuritypatchday - Vendor Advisory
CVSS v2 : unknown
v3 : 4.7
v2 : unknown
v3 : 5.4
CWE NVD-CWE-noinfo

13 Aug 2024, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-13 04:15

Updated : 2024-09-11 17:52


NVD link : CVE-2024-41732

Mitre link : CVE-2024-41732

CVE.ORG link : CVE-2024-41732


JSON object : View

Products Affected

sap

  • netweaver_application_server_abap
CWE
NVD-CWE-noinfo CWE-284

Improper Access Control