First published: Tue Jul 09 2024(Updated: )
Under certain conditions SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to access remote-enabled function module with no further authorization which would otherwise be restricted, the function can be used to read non-sensitive information with low impact on confidentiality of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver AS ABAP Kernel | ||
SAP ABAP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37180 is classified as a low-severity vulnerability affecting SAP NetWeaver Application Server for ABAP and ABAP Platform.
To remediate CVE-2024-37180, apply the relevant SAP security patches as recommended by SAP.
CVE-2024-37180 affects SAP NetWeaver Application Server for ABAP and SAP ABAP Platform.
CVE-2024-37180 allows unauthorized access to remote-enabled function modules, which can be exploited to read non-sensitive information.
As of now, there are no public reports indicating active exploitation of CVE-2024-37180.