First published: Tue Nov 12 2024(Updated: )
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously crafted http request which could cause a null pointer dereference in the kernel. This dereference will result in the system crashing and rebooting, causing the system to be temporarily unavailable. There is no impact on Confidentiality or Integrity.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver AS ABAP Kernel | ||
SAP ABAP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-47586 is considered a critical vulnerability due to its potential to cause system crashes.
To mitigate CVE-2024-47586, users should apply the latest patches provided by SAP for the affected SAP NetWeaver Application Server for ABAP and ABAP Platform.
CVE-2024-47586 affects systems running SAP NetWeaver Application Server for ABAP and the ABAP Platform.
Yes, CVE-2024-47586 can be exploited by an unauthenticated attacker remotely through a crafted HTTP request.
The impact of CVE-2024-47586 includes system crashes and reboots due to a null pointer dereference in the kernel.