CVE-2024-44115: Multiple vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform
The RFC enabled function module allows a low privileged user to add URLs to any user's workplace favourites. This vulnerability could be utilized to identify usernames and access information about targeted user's workplaces, and nodes. There is low impact on integrity of the application
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-44115?
The severity of CVE-2024-44115 is considered low, impacting the integrity of the application but allowing information disclosure.
How do I fix CVE-2024-44115?
To fix CVE-2024-44115, it is recommended to apply the latest security patch provided by SAP for your affected product version.
Who is affected by CVE-2024-44115?
CVE-2024-44115 affects users of SAP NetWeaver Application Server for ABAP and SAP ABAP Platform.
What can attackers do with CVE-2024-44115?
Attackers can exploit CVE-2024-44115 to add URLs to any user's workplace favorites, potentially revealing usernames and gaining access to user information.
Is CVE-2024-44115 relevant to all users of SAP products?
CVE-2024-44115 is particularly relevant to low privileged users in SAP systems, as it involves unauthorized manipulation of workplace favorites.