CVE-2024-41728: Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform
Due to missing authorization check, SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker logged in as a developer to read objects contained in a package. This causes an impact on confidentiality, as this attacker would otherwise not have access to view these objects.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41728?
CVE-2024-41728 has been assessed as having a high severity due to its impact on confidentiality.
How do I fix CVE-2024-41728?
To mitigate CVE-2024-41728, it is recommended to apply the latest patches provided by SAP for affected versions of NetWeaver Application Server for ABAP.
What systems are affected by CVE-2024-41728?
CVE-2024-41728 affects multiple versions of SAP NetWeaver Application Server for ABAP, specifically versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, and 912.
What kind of attack does CVE-2024-41728 enable?
CVE-2024-41728 enables an attacker logged in as a developer to read unauthorized objects contained within a package.
Is there a workaround for CVE-2024-41728?
Currently, no official workaround is provided for CVE-2024-41728, so applying security patches is the recommended course of action.