CVE-2024-44117: Multiple vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform
Published Sep 10, 2024
·Updated
The RFC enabled function module allows a low privileged user to perform various actions, such as modifying the URLs of any user's favourite nodes and workbook ID. There is low impact on integrity and availability of the application.
Affected Software
2 affected components
SAP NetWeaver Application Server for ABAP
SAP ABAP Platform
Event History
Sep 10, 2024
CVE Published
via MITRE·04:25 AM
Data Sourced
via MITRE·04:25 AM
DescriptionSeverity
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-44117?
CVE-2024-44117 is classified with low impact on integrity and availability of the application.
2
How do I fix CVE-2024-44117?
To fix CVE-2024-44117, ensure that proper user permissions are enforced to prevent low privileged users from executing unauthorized actions.
3
What software is affected by CVE-2024-44117?
CVE-2024-44117 affects SAP NetWeaver Application Server for ABAP and SAP ABAP Platform.
4
What actions can a low privileged user perform due to CVE-2024-44117?
A low privileged user can modify the URLs of any user's favorite nodes and workbook ID.
5
Is there a workaround for CVE-2024-44117?
Implementing stricter controls on user permissions serves as a workaround for CVE-2024-44117.