The RFC enabled function module allows a low privileged user to read any user's workplace favourites and user menu along with all the specific data of each node. Usernames can be enumerated by exploiting vulnerability. There is low impact on confidentiality of the application.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-39585 | The RFC enabled function module allows a low privileged user to read any user's workplace favourites and user menu along with all the specific data of each node. Usernames can be enumerated by exploiting vulnerability. There is low impact on confidentiality of the application. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 10 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Sep 2024 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The RFC enabled function module allows a low privileged user to read any user's workplace favourites and user menu along with all the specific data of each node. Usernames can be enumerated by exploiting vulnerability. There is low impact on confidentiality of the application. | |
| Title | Multiple vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-09-10T13:37:57.456Z
Reserved: 2024-07-31T04:09:36.223Z
Link: CVE-2024-42380
Updated: 2024-09-10T13:37:48.598Z
Status : Awaiting Analysis
Published: 2024-09-10T03:15:02.653
Modified: 2024-09-10T12:09:50.377
Link: CVE-2024-42380
No data.
OpenCVE Enrichment
No data.
EUVD