CVE-2024-47585: Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization checks, resulting in privilege escalation. While authorizations for import and export are distinguished, a single authorization is applied for both, which may contribute to these risks. On successful exploitation, this can result in potential security concerns. However, it has no impact on the integrity and availability of the application and may have only a low impact on data confidentiality.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47585?
CVE-2024-47585 is considered a high-severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2024-47585?
To fix CVE-2024-47585, ensure that you apply the latest SAP security patches and updates provided by SAP.
Who is affected by CVE-2024-47585?
CVE-2024-47585 affects users of SAP NetWeaver Application Server for ABAP and the ABAP Platform.
What type of vulnerability is CVE-2024-47585?
CVE-2024-47585 is an improper authorization vulnerability that can lead to privilege escalation.
What are the potential impacts of CVE-2024-47585?
Exploiting CVE-2024-47585 can allow authenticated attackers to gain unauthorized access levels, compromising system integrity.