Vulnerability Description
SAP shared service framework allows an authenticated non-administrative user to call a remote-enabled function, which will allow them to insert value entries into a non-sensitive table, causing low impact on integrity of the application
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Shared Service Framework | sap_bs_fnd_702 |
Related Weaknesses (CWE)
References
- https://me.sap.com/notes/3474590Permissions Required
- https://url.sap/sapsecuritypatchdayVendor Advisory
FAQ
What is CVE-2024-42377?
CVE-2024-42377 is a vulnerability with a CVSS score of 4.3 (MEDIUM). SAP shared service framework allows an authenticated non-administrative user to call a remote-enabled function, which will allow them to insert value entries into a non-sensitive table, causing low im...
How severe is CVE-2024-42377?
CVE-2024-42377 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-42377?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Shared Service Framework.