CVE-2024-22131 Information
Feb 14, 2024
cve
Description
In SAP ABA (Application Basis) - versions 700 701 702 731 740 750 751 752 75C 75I an attacker authenticated as a user with a remote execution authorization can use a vulnerable interface. This allows the attacker to use the interface to invoke an application function to perform actions which they would not normally be permitted to perform. Depending on the function executed the attack can read or modify any user/business data and can make the entire system unavailable.
Reference
https://me.sap.com/notes/3420923 https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
Share on: