CVE-2024-41732

Description

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to craft a URL link that could bypass allowlist controls. Depending on the web applications provided by this server, the attacker might inject CSS code or links into the web application that could allow the attacker to read or modify information. There is no impact on availability of application.

Risk Information

Base Score
5.4
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.152

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 755Windows
Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 756Windows
Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 757Windows
Multiple Vulnerabilities are affected in SAP NetWeaver Application Server ABAP 758Windows
Vulnerabilities CVE-2024-41732,CVE-2024-41734 are affected in SAP NetWeaver Application Server ABAP sap_basis_700Windows
Vulnerabilities CVE-2024-41732,CVE-2024-41734 are affected in SAP NetWeaver Application Server ABAP sap_basis_701Windows
Vulnerabilities CVE-2024-41732,CVE-2024-41734 are affected in SAP NetWeaver Application Server ABAP sap_basis_702Windows
Vulnerabilities CVE-2024-41732,CVE-2024-41734 are affected in SAP NetWeaver Application Server ABAP sap_basis_731Windows
Vulnerabilities CVE-2024-41732,CVE-2024-41734 are affected in SAP NetWeaver Application Server ABAP sap_basis_912Windows
Vulnerabilities CVE-2024-41732 are affected in SAP NetWeaver Application Server ABAP sap_ui_754Windows
Vulnerabilities CVE-2024-41732,CVE-2024-41734 are affected in SAP NetWeaver and ABAP platform (ST-PI) sap_basis_700Windows
Vulnerabilities CVE-2024-41732,CVE-2024-41734 are affected in SAP NetWeaver and ABAP platform (ST-PI) sap_basis_701Windows
Vulnerabilities CVE-2024-41732,CVE-2024-41734 are affected in SAP NetWeaver and ABAP platform (ST-PI) sap_basis_702Windows
Vulnerabilities CVE-2024-41732,CVE-2024-41734 are affected in SAP NetWeaver and ABAP platform (ST-PI) sap_basis_731Windows
Vulnerabilities CVE-2024-41732,CVE-2024-41734 are affected in SAP NetWeaver and ABAP platform (ST-PI) sap_basis_912Windows
Vulnerabilities CVE-2024-41732 are affected in SAP NetWeaver and ABAP platform (ST-PI) sap_ui_754Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234