CVE-2024-22124: Information Disclosure vulnerability in SAP NetWeaver Internet Communication Manager
Under certain conditions, Internet Communication Manager (ICM) or SAP Web Dispatcher - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, KRNL64NUC 7.22, KRNL64NUC 7.22EXT, WEBDISP 7.22EXT, WEBDISP 7.53, WEBDISP 7.54, could allow an attacker to access information which would otherwise be restricted causing high impact on confidentiality.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SAP NetWeaver Internet Communication Manager (ICM) / SAP Web Dispatcherto a version that resolves this vulnerability.Fixed in KERNEL 7.22 - Upgrade
Upgrade
SAP NetWeaver Internet Communication Manager (ICM) / SAP Web Dispatcherto a version that resolves this vulnerability.Fixed in KERNEL 7.53 - Upgrade
Upgrade
SAP NetWeaver Internet Communication Manager (ICM) / SAP Web Dispatcherto a version that resolves this vulnerability.Fixed in KERNEL 7.54 - Upgrade
Upgrade
SAP NetWeaver Internet Communication Manager (ICM) / SAP Web Dispatcherto a version that resolves this vulnerability.Fixed in KRNL64UC 7.22 - Upgrade
Upgrade
SAP NetWeaver Internet Communication Manager (ICM) / SAP Web Dispatcherto a version that resolves this vulnerability.Fixed in KRNL64UC 7.22EXT - Upgrade
Upgrade
SAP NetWeaver Internet Communication Manager (ICM) / SAP Web Dispatcherto a version that resolves this vulnerability.Fixed in KRNL64UC 7.53 - Upgrade
Upgrade
SAP NetWeaver Internet Communication Manager (ICM) / SAP Web Dispatcherto a version that resolves this vulnerability.Fixed in KRNL64NUC 7.22 - Upgrade
Upgrade
SAP NetWeaver Internet Communication Manager (ICM) / SAP Web Dispatcherto a version that resolves this vulnerability.Fixed in KRNL64NUC 7.22_EXT - Upgrade
Upgrade
SAP NetWeaver Internet Communication Manager (ICM) / SAP Web Dispatcherto a version that resolves this vulnerability.Fixed in WEBDISP 7.22_EXT - Upgrade
Upgrade
SAP NetWeaver Internet Communication Manager (ICM) / SAP Web Dispatcherto a version that resolves this vulnerability.Fixed in WEBDISP 7.53 - Upgrade
Upgrade
SAP NetWeaver Internet Communication Manager (ICM) / SAP Web Dispatcherto a version that resolves this vulnerability.Fixed in WEBDISP 7.54
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22124?
CVE-2024-22124 has been rated with high severity due to its potential to allow unauthorized access under specific conditions.
How do I fix CVE-2024-22124?
To remediate CVE-2024-22124, upgrade to the latest versions of SAP NetWeaver KERNEL 7.54 or other affected components as indicated by SAP's security guidelines.
What versions are affected by CVE-2024-22124?
CVE-2024-22124 affects SAP NetWeaver KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, and certain other specified configurations.
What products are impacted by CVE-2024-22124?
The products impacted by CVE-2024-22124 include Internet Communication Manager (ICM) and SAP Web Dispatcher among versions of SAP NetWeaver.
Is CVE-2024-22124 currently being exploited?
As of now, no public exploitation of CVE-2024-22124 has been reported, but it is crucial to apply security patches promptly.