First published: Tue Jun 11 2024(Updated: )
Due to unrestricted access to the Meta Model Repository services in SAP NetWeaver AS Java, attackers can perform DoS attacks on the application, which may prevent legitimate users from accessing it. This can result in no impact on confidentiality and integrity but a high impact on the availability of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver AS JAVA | =mmr_server_7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-34688 has a high severity due to the potential for denial of service attacks affecting application availability.
CVE-2024-34688 affects users of SAP NetWeaver AS Java specifically on version mmr_server_7.5.
Attackers can perform denial of service (DoS) attacks through unrestricted access to the Meta Model Repository services.
Organizations should implement access controls and monitor usage of the Meta Model Repository services to mitigate CVE-2024-34688.
CVE-2024-34688 can lead to significant availability issues, preventing legitimate users from accessing the application.