First published: Tue Sep 10 2024(Updated: )
The RFC enabled function module allows a low privileged user to add URLs to any user's workplace favourites. This vulnerability could be utilized to identify usernames and access information about targeted user's workplaces, and nodes. There is low impact on integrity of the application
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver AS ABAP Kernel | ||
SAP ABAP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-44115 is considered low, impacting the integrity of the application but allowing information disclosure.
To fix CVE-2024-44115, it is recommended to apply the latest security patch provided by SAP for your affected product version.
CVE-2024-44115 affects users of SAP NetWeaver Application Server for ABAP and SAP ABAP Platform.
Attackers can exploit CVE-2024-44115 to add URLs to any user's workplace favorites, potentially revealing usernames and gaining access to user information.
CVE-2024-44115 is particularly relevant to low privileged users in SAP systems, as it involves unauthorized manipulation of workplace favorites.