CVE Published: 13/08/2024 |
CVE Updated: 13/08/2024 |
CVE Year: 2024 Source: sap |
Vendor: SAP_SE |
Product: SAP NetWeaver Application Server ABAP and ABAP Platform Status : PUBLISHED
CVE-2024-41734 Description
Due to missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform, an authenticated attacker could call an underlying transaction, which leads to disclosure of user related information. There is no impact on integrity or availability.
Metrics
CVSS Version: 3.1 |
Base Score: 4.3 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N