CVE-2024-24743: XXE vulnerability in SAP NetWeaver AS Java (Guided Procedures)
SAP NetWeaver AS Java (CAF - Guided Procedures) - version 7.50, allows an unauthenticated attacker to submit a malicious request with a crafted XML file over the network, which when parsed will enable him to access sensitive files and data but not modify them. There are expansion limits in place so that availability is not affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24743?
CVE-2024-24743 has been categorized as a critical vulnerability due to the potential for unauthorized access to sensitive files.
How do I fix CVE-2024-24743?
To mitigate CVE-2024-24743, ensure that your SAP NetWeaver AS Java version is updated to the latest patch released by SAP.
Who is affected by CVE-2024-24743?
CVE-2024-24743 affects users running SAP NetWeaver AS Java version 7.50.
What types of attacks are possible with CVE-2024-24743?
CVE-2024-24743 allows unauthenticated attackers to access sensitive files through crafted XML requests.
Can CVE-2024-24743 be exploited remotely?
Yes, CVE-2024-24743 can be exploited remotely over the network without authentication.