In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can be used to expose credentials for a remote service. These credentials can then be further exploited to completely compromise the remote service, potentially resulting in a significant impact on the confidentiality, integrity, and availability of the application.
                
            References
                    Configurations
                    No configuration.
History
                    10 Dec 2024, 01:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-12-10 01:15
Updated : 2024-12-10 01:15
NVD link : CVE-2024-54198
Mitre link : CVE-2024-54198
CVE.ORG link : CVE-2024-54198
JSON object : View
Products Affected
                No product.
CWE
                
                    
                        
                        CWE-914
                        
            Improper Control of Dynamically-Identified Variables
