Under certain conditions SAP NetWeaver
Application Server for ABAP and ABAP Platform allows an attacker to access
remote-enabled function module with no further authorization which would
otherwise be restricted, the function can be used to read non-sensitive
information with low impact on confidentiality of the application.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-36486 Under certain conditions SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to access remote-enabled function module with no further authorization which would otherwise be restricted, the function can be used to read non-sensitive information with low impact on confidentiality of the application.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 29 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap sap Basis
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:sap:sap_basis:700:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:701:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:702:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:731:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:740:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:750:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:751:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:752:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:753:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:754:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:755:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:756:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:757:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_basis:758:*:*:*:*:*:*:*
Vendors & Products Sap
Sap sap Basis

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2024-08-02T03:50:55.233Z

Reserved: 2024-06-04T07:49:42.492Z

Link: CVE-2024-37180

cve-icon Vulnrichment

Updated: 2024-08-02T03:50:55.233Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-09T05:15:12.033

Modified: 2025-10-29T14:44:33.727

Link: CVE-2024-37180

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.