SAP NetWeaver AS ABAP Unauth URL Bypass Allowlist
CVE-2024-41732 Published on August 13, 2024
Improper Access Control in SAP Netweaver Application Server ABAP
SAP NetWeaver Application Server ABAP allows
an unauthenticated attacker to craft a URL link that could bypass allowlist
controls. Depending on the web applications provided by this server, the
attacker might inject CSS code or links into the web application that could
allow the attacker to read or modify information. There is no impact on
availability of application.
Vulnerability Analysis
CVE-2024-41732 is exploitable with network access, requires user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is an Authorization Vulnerability?
The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVE-2024-41732 has been classified to as an Authorization vulnerability or weakness.
Products Associated with CVE-2024-41732
Want to know whenever a new CVE is published for SAP Netweaver Application Server Abap? stack.watch will email you.
Affected Versions
SAP_SE SAP NetWeaver Application Server ABAP:- Version SAP_UI 754 is affected.
- Version 755 is affected.
- Version 756 is affected.
- Version 757 is affected.
- Version 758 is affected.
- Version SAP_BASIS 700 is affected.
- Version SAP_BASIS 701 is affected.
- Version SAP_BASIS 702 is affected.
- Version SAP_BASIS 731 is affected.
- Version SAP_BASIS 912 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.