SAP Transportation Management (Collaboration
Portal) allows an attacker with non-administrative privileges to send a crafted
request from a vulnerable web application. This will trigger the application
handler to send a request to an unintended service, which may reveal
information about that service. The information obtained could be used to
target internal systems behind firewalls that are normally inaccessible to an
attacker from the external network, resulting in a Server-Side Request Forgery
vulnerability. There is no effect on integrity or availability of the
application.
Portal) allows an attacker with non-administrative privileges to send a crafted
request from a vulnerable web application. This will trigger the application
handler to send a request to an unintended service, which may reveal
information about that service. The information obtained could be used to
target internal systems behind firewalls that are normally inaccessible to an
attacker from the external network, resulting in a Server-Side Request Forgery
vulnerability. There is no effect on integrity or availability of the
application.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-36477 | SAP Transportation Management (Collaboration Portal) allows an attacker with non-administrative privileges to send a crafted request from a vulnerable web application. This will trigger the application handler to send a request to an unintended service, which may reveal information about that service. The information obtained could be used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. There is no effect on integrity or availability of the application. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 09 Sep 2024 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap saptmui Sap transportation Management |
|
| CPEs | cpe:2.3:a:sap:saptmui:140:*:*:*:*:*:*:* cpe:2.3:a:sap:saptmui:150:*:*:*:*:*:*:* cpe:2.3:a:sap:saptmui:160:*:*:*:*:*:*:* cpe:2.3:a:sap:saptmui:170:*:*:*:*:*:*:* cpe:2.3:a:sap:transportation_management:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sap
Sap saptmui Sap transportation Management |
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-08-02T03:50:54.664Z
Reserved: 2024-06-04T07:49:42.491Z
Link: CVE-2024-37171
Updated: 2024-08-02T03:50:54.664Z
Status : Modified
Published: 2024-07-09T05:15:11.407
Modified: 2024-11-21T09:23:21.233
Link: CVE-2024-37171
No data.
OpenCVE Enrichment
No data.
EUVD