Vulnerability Description
Under certain conditions SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to access remote-enabled function module with no further authorization which would otherwise be restricted, the function can be used to read non-sensitive information with low impact on confidentiality of the application.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Sap Basis | 700 |
Related Weaknesses (CWE)
References
- https://me.sap.com/notes/3454858Permissions Required
- https://url.sap/sapsecuritypatchdayPatch
- https://me.sap.com/notes/3454858Permissions Required
- https://url.sap/sapsecuritypatchdayPatch
FAQ
What is CVE-2024-37180?
CVE-2024-37180 is a vulnerability with a CVSS score of 4.1 (MEDIUM). Under certain conditions SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to access remote-enabled function module with no further authorization which would otherwise be ...
How severe is CVE-2024-37180?
CVE-2024-37180 has been rated MEDIUM with a CVSS base score of 4.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-37180?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Sap Basis.