SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the server, which otherwise would be restricted.This attack is possible only if a Web Dispatcher or some sort of Proxy Server is in use and the file in question was previously opened or downloaded in an application based on SAP GUI for HTML Technology. This will not compromise the application's integrity or availability.
History

Tue, 12 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Sap Se
Sap Se sap Netweaver And Abap Platform
Weaknesses CWE-276
CPEs cpe:2.3:a:sap_se:sap_netweaver_and_abap_platform:*:*:*:*:*:*:*:*
Vendors & Products Sap Se
Sap Se sap Netweaver And Abap Platform
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 Nov 2024 00:45:00 +0000

Type Values Removed Values Added
Description SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the server, which otherwise would be restricted.This attack is possible only if a Web Dispatcher or some sort of Proxy Server is in use and the file in question was previously opened or downloaded in an application based on SAP GUI for HTML Technology. This will not compromise the application's integrity or availability.
Title Information Disclosure Vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2024-11-12T00:27:17.815Z

Updated: 2024-11-12T14:49:44.745Z

Reserved: 2024-09-27T20:05:59.022Z

Link: CVE-2024-47593

cve-icon Vulnrichment

Updated: 2024-11-12T14:49:31.250Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-12T01:15:05.480

Modified: 2024-11-12T15:35:13.233

Link: CVE-2024-47593

cve-icon Redhat

No data.