Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-41732


SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that could bypass allowlist controls. Depending on the web applications provided by this server, the attacker might inject CSS code or links into the web application that could allow the attacker to read or modify information. There is no impact on availability of application.


Published

2024-08-13T04:15:08.637

Last Modified

2024-09-11T17:52:39.477

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.7 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-284
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap netweaver_application_server_abap 755 Yes
Application sap netweaver_application_server_abap 756 Yes
Application sap netweaver_application_server_abap 757 Yes
Application sap netweaver_application_server_abap 758 Yes
Application sap netweaver_application_server_abap sap_basis_700 Yes
Application sap netweaver_application_server_abap sap_basis_701 Yes
Application sap netweaver_application_server_abap sap_basis_702 Yes
Application sap netweaver_application_server_abap sap_basis_731 Yes
Application sap netweaver_application_server_abap sap_basis_912 Yes
Application sap netweaver_application_server_abap sap_ui_754 Yes

References