SAP CRM ABAP (Insights Management) allows an authenticated attacker to enumerate HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in information disclosure. It has no impact on integrity and availability of the application.
History

Thu, 12 Sep 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap crm Abap Insights Management
CPEs cpe:2.3:a:sap:crm_abap_insights_management:bbpcrm_700:*:*:*:*:*:*:*
cpe:2.3:a:sap:crm_abap_insights_management:bbpcrm_701:*:*:*:*:*:*:*
cpe:2.3:a:sap:crm_abap_insights_management:bbpcrm_702:*:*:*:*:*:*:*
cpe:2.3:a:sap:crm_abap_insights_management:bbpcrm_712:*:*:*:*:*:*:*
cpe:2.3:a:sap:crm_abap_insights_management:bbpcrm_713:*:*:*:*:*:*:*
cpe:2.3:a:sap:crm_abap_insights_management:bbpcrm_714:*:*:*:*:*:*:*
Vendors & Products Sap
Sap crm Abap Insights Management

Wed, 14 Aug 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 13 Aug 2024 04:15:00 +0000

Type Values Removed Values Added
Description SAP CRM ABAP (Insights Management) allows an authenticated attacker to enumerate HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in information disclosure. It has no impact on integrity and availability of the application.
Title Server-Side Request Forgery (SSRF) in SAP CRM ABAP (Insights Management)
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2024-08-13T03:55:04.128Z

Updated: 2024-08-14T16:43:20.026Z

Reserved: 2024-07-22T08:06:52.677Z

Link: CVE-2024-41737

cve-icon Vulnrichment

Updated: 2024-08-14T16:43:09.628Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-13T04:15:10.003

Modified: 2024-09-12T13:49:41.953

Link: CVE-2024-41737

cve-icon Redhat

No data.