SAP CRM (WebClient UI Framework) allows an
authenticated attacker to enumerate accessible HTTP endpoints in the internal
network by specially crafting HTTP requests. On successful exploitation this
can result in information disclosure. It has no impact on integrity and
availability of the application.
References
Link | Resource |
---|---|
https://url.sap/sapsecuritypatchday | Vendor Advisory |
https://me.sap.com/notes/3467377 | Permissions Required |
Configurations
Configuration 1 (hide)
|
History
29 Aug 2024, 19:04
Type | Values Removed | Values Added |
---|---|---|
First Time |
Sap
Sap customer Relationship Management S4fnd Sap customer Relationship Management Webclient Ui |
|
References | () https://me.sap.com/notes/3467377 - Permissions Required | |
References | () https://url.sap/sapsecuritypatchday - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.7 |
CPE | cpe:2.3:a:sap:customer_relationship_management_s4fnd:108:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:731:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_s4fnd:102:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_s4fnd:105:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:747:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_s4fnd:107:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:800:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_s4fnd:104:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:746:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:801:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_s4fnd:106:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:701:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_s4fnd:103:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:748:*:*:*:*:*:*:* |
09 Jul 2024, 04:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-09 04:15
Updated : 2024-08-29 19:04
NVD link : CVE-2024-39598
Mitre link : CVE-2024-39598
JSON object : View
Products Affected
sap
- customer_relationship_management_webclient_ui
- customer_relationship_management_s4fnd
CWE
CWE-918
Server-Side Request Forgery (SSRF)