CVE-2024-44114: Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform
Published Sep 10, 2024
·Updated
SAP NetWeaver Application Server for ABAP and ABAP Platform allow users with high privileges to execute a program that reveals data over the network. This results in a minimal impact on confidentiality of the application.
Affected Software
13 affected components
SAP NetWeaver Application Server ABAP=702
SAP NetWeaver Application Server ABAP=731
SAP NetWeaver Application Server ABAP=740
SAP NetWeaver Application Server ABAP=750
SAP NetWeaver Application Server ABAP=751
SAP NetWeaver Application Server ABAP=752
SAP NetWeaver Application Server ABAP=753
SAP NetWeaver Application Server ABAP=754
SAP NetWeaver Application Server ABAP=755
SAP NetWeaver Application Server ABAP=756
SAP NetWeaver Application Server ABAP=757
SAP NetWeaver Application Server ABAP=758
SAP NetWeaver Application Server ABAP=912
Remediation
Patch Available
Event History
Sep 10, 2024
CVE Published
via MITRE·03:06 AM
Data Sourced
via MITRE·03:06 AM
DescriptionSeverity
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-44114?
The severity of CVE-2024-44114 is minimal, affecting confidentiality.
2
How do I fix CVE-2024-44114?
Fixing CVE-2024-44114 involves applying the relevant SAP security patches or updates.
3
Which versions of SAP NetWeaver Application Server for ABAP are affected by CVE-2024-44114?
CVE-2024-44114 affects versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758, and 912 of SAP NetWeaver Application Server for ABAP.
4
What are the potential impacts of CVE-2024-44114?
The potential impact of CVE-2024-44114 includes unauthorized data exposure over the network.
5
Can user privileges affect CVE-2024-44114?
Yes, users with high privileges may exploit CVE-2024-44114 to execute a program that reveals sensitive data.