CVE Published: 13/08/2024 |
CVE Updated: 14/08/2024 |
CVE Year: 2024 Source: sap |
Vendor: SAP_SE |
Product: SAP CRM ABAP (Insights Management) Status : PUBLISHED
CVE-2024-41737 Description
SAP CRM ABAP (Insights
Management) allows an authenticated attacker to enumerate HTTP endpoints in the
internal network by specially crafting HTTP requests. On successful
exploitation this can result in information disclosure. It has no impact on
integrity and availability of the application.
Metrics
CVSS Version: 3.1 |
Base Score: 5 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N