CVE-2024-34689: [CVE-2024-34689] Server-Side Request Forgery in SAP Business Workflow (WebFlow Services)
WebFlow Services of SAP Business Workflow allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in information disclosure. It has no impact on integrity and availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34689?
CVE-2024-34689 is classified as a medium severity vulnerability.
How do I fix CVE-2024-34689?
To fix CVE-2024-34689, update your SAP Business Workflow to the latest patched version from SAP.
What types of attacks are possible with CVE-2024-34689?
CVE-2024-34689 allows authenticated attackers to enumerate HTTP endpoints, potentially leading to information disclosure.
Which SAP products are affected by CVE-2024-34689?
CVE-2024-34689 affects various versions of SAP Business Workflow and SAP Basis, specifically from versions 700 to 758.
Can CVE-2024-34689 impact system integrity?
CVE-2024-34689 does not impact the integrity or availability of the system, only the confidentiality of information.