Show filters
502 Total Results
Displaying 21-30 of 502
Sort by:
Attacker Value
Unknown
CVE-2024-54197
Disclosure Date: December 10, 2024 (last updated December 21, 2024)
SAP NetWeaver Administrator(System Overview) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in Server-Side Request Forgery (SSRF) which could have a low impact on integrity and confidentiality of data. It has no impact on availability of the application.
0
Attacker Value
Unknown
CVE-2024-47585
Disclosure Date: December 10, 2024 (last updated December 21, 2024)
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization checks, resulting in privilege escalation. While authorizations for import and export are distinguished, a single authorization is applied for both, which may contribute to these risks. On successful exploitation, this can result in potential security concerns. However, it has no impact on the integrity and availability of the application and may have only a low impact on data confidentiality.
0
Attacker Value
Unknown
CVE-2024-47582
Disclosure Date: December 10, 2024 (last updated December 21, 2024)
Due to missing validation of XML input, an unauthenticated attacker could send malicious input to an endpoint which leads to XML Entity Expansion attack. This causes limited impact on availability of the application.
0
Attacker Value
Unknown
CVE-2024-47580
Disclosure Date: December 10, 2024 (last updated December 21, 2024)
An attacker authenticated as an administrator can use an exposed webservice to create a PDF with an embedded attachment. By specifying the file to be an internal server file and subsequently downloading the generated PDF, the attacker can read any file on the server with no effect on integrity or availability.
0
Attacker Value
Unknown
CVE-2024-47579
Disclosure Date: December 10, 2024 (last updated December 21, 2024)
An attacker authenticated as an administrator can use an exposed webservice to upload or download a custom PDF font file on the system server. Using the upload functionality to copy an internal file into a font file and subsequently using the download functionality to retrieve that file allows the attacker to read any file on the server with no effect on integrity or availability
0
Attacker Value
Unknown
CVE-2024-47578
Disclosure Date: December 10, 2024 (last updated December 21, 2024)
Adobe Document Service allows an attacker with administrator privileges to send a crafted request from a vulnerable web application. It is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. On successful exploitation, the attacker can read or modify any file and/or make the entire system unavailable.
0
Attacker Value
Unknown
CVE-2024-47593
Disclosure Date: November 12, 2024 (last updated November 12, 2024)
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the server, which otherwise would be restricted.This attack is possible only if a Web Dispatcher or some sort of Proxy Server is in use and the file in question was previously opened or downloaded in an application based on SAP GUI for HTML Technology. This will not compromise the application's integrity or availability.
0
Attacker Value
Unknown
CVE-2024-47592
Disclosure Date: November 12, 2024 (last updated November 12, 2024)
SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality in order to identify the legitimate user IDs. This has an impact on confidentiality but not on integrity or availability.
0
Attacker Value
Unknown
CVE-2024-47588
Disclosure Date: November 12, 2024 (last updated November 12, 2024)
In SAP NetWeaver Java (Software Update Manager 1.1), under certain conditions when a software upgrade encounters errors, credentials are written in plaintext to a log file. An attacker with local access to the server, authenticated as a non-administrative user, can acquire the credentials from the logs. This leads to a high impact on confidentiality, with no impact on integrity or availability.
0
Attacker Value
Unknown
CVE-2024-47586
Disclosure Date: November 12, 2024 (last updated November 12, 2024)
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously crafted http request which could cause a null pointer dereference in the kernel. This dereference will result in the system crashing and rebooting, causing the system to be temporarily unavailable. There is no impact on Confidentiality or Integrity.
0