The RFC enabled function module allows a low privileged user to add URLs to any user's workplace favourites. This vulnerability could be utilized to identify usernames and access information about targeted user's workplaces, and nodes. There is low impact on integrity of the application
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-40875 | The RFC enabled function module allows a low privileged user to add URLs to any user's workplace favourites. This vulnerability could be utilized to identify usernames and access information about targeted user's workplaces, and nodes. There is low impact on integrity of the application |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 17 Sep 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Sep 2024 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The RFC enabled function module allows a low privileged user to add URLs to any user's workplace favourites. This vulnerability could be utilized to identify usernames and access information about targeted user's workplaces, and nodes. There is low impact on integrity of the application | |
| Title | Multiple vulnerabilities in SAP NetWeaver Application Server for ABAP and ABAP Platform | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-09-16T16:16:14.697Z
Reserved: 2024-08-20T20:22:59.937Z
Link: CVE-2024-44115
Updated: 2024-09-10T13:27:34.665Z
Status : Awaiting Analysis
Published: 2024-09-10T03:15:03.293
Modified: 2024-09-10T12:09:50.377
Link: CVE-2024-44115
No data.
OpenCVE Enrichment
No data.
EUVD