SAP CRM (WebClient UI Framework) allows an
authenticated attacker to enumerate accessible HTTP endpoints in the internal
network by specially crafting HTTP requests. On successful exploitation this
can result in information disclosure. It has no impact on integrity and
availability of the application.
Metrics
Affected Vendors & Products
References
History
Thu, 29 Aug 2024 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sap
Sap customer Relationship Management S4fnd Sap customer Relationship Management Webclient Ui |
|
CPEs | cpe:2.3:a:sap:customer_relationship_management_s4fnd:102:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_s4fnd:103:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_s4fnd:104:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_s4fnd:105:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_s4fnd:106:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_s4fnd:107:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_s4fnd:108:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:701:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:731:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:746:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:747:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:748:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:800:*:*:*:*:*:*:* cpe:2.3:a:sap:customer_relationship_management_webclient_ui:801:*:*:*:*:*:*:* |
|
Vendors & Products |
Sap
Sap customer Relationship Management S4fnd Sap customer Relationship Management Webclient Ui |
MITRE
Status: PUBLISHED
Assigner: sap
Published: 2024-07-09T04:04:41.283Z
Updated: 2024-08-02T04:26:15.953Z
Reserved: 2024-06-26T09:58:24.096Z
Link: CVE-2024-39598
Vulnrichment
Updated: 2024-07-09T19:02:56.236Z
NVD
Status : Modified
Published: 2024-07-09T04:15:14.860
Modified: 2024-11-21T09:28:05.417
Link: CVE-2024-39598
Redhat
No data.