CVE-2024-54197 Information
Dec 11, 2024
cve
Description
SAP NetWeaver Administrator(System Overview) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in Server-Side Request Forgery (SSRF) which could have a low impact on integrity and confidentiality of data. It has no impact on availability of the application.
Reference
https://me.sap.com/notes/3542543 https://url.sap/sapsecuritypatchday https://url.sap/sapsecuritypatchday
Share on: