CVE-2024-41734: Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform
Due to missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform, an authenticated attacker could call an underlying transaction, which leads to disclosure of user related information. There is no impact on integrity or availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41734?
CVE-2024-41734 is classified with a medium severity level due to its potential for an authenticated attacker to access user-related information.
How do I fix CVE-2024-41734?
To mitigate CVE-2024-41734, apply the latest security patches provided by SAP for the affected versions of the SAP NetWeaver Application Server ABAP.
What are the affected versions of SAP NetWeaver Application Server ABAP for CVE-2024-41734?
CVE-2024-41734 affects SAP NetWeaver Application Server ABAP versions from sap_basis_700 to sap_basis_912.
What type of information could be disclosed due to CVE-2024-41734?
CVE-2024-41734 can lead to the disclosure of user-related information, compromising user privacy.
Is there any impact on integrity or availability from CVE-2024-41734?
CVE-2024-41734 does not impact the integrity or availability of the system, it only affects confidentiality.