First published: Tue Sep 10 2024(Updated: )
The RFC enabled function module allows a low privileged user to perform various actions, such as modifying the URLs of any user's favourite nodes and workbook ID. There is low impact on integrity and availability of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver AS ABAP Kernel | ||
SAP ABAP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-44117 is classified with low impact on integrity and availability of the application.
To fix CVE-2024-44117, ensure that proper user permissions are enforced to prevent low privileged users from executing unauthorized actions.
CVE-2024-44117 affects SAP NetWeaver Application Server for ABAP and SAP ABAP Platform.
A low privileged user can modify the URLs of any user's favorite nodes and workbook ID.
Implementing stricter controls on user permissions serves as a workaround for CVE-2024-44117.