VDB

CVE-2026-24311

CVE-2026-24311 PUBLISHED CVSS 5.599999904632568 MEDIUM

De multiples vulnérabilités ont été découvertes dans les produits SAP. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une injection SQL (SQLi).

EPSS 0.01% · 1.1th percentile

Risk Scores

CVSS 3.1
5.599999904632568
CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L
EPSS Score
0.01%
1.1th percentile

Affected Products

VendorProductVersions
SAPNetWeaver
SAP_SESAP Customer Checkout 2.0SAP_CUSTOMER_CHECKOUT 2.0, SAP_CUSTOMER_CHECKOUT 2.0
SAPN/A
Apache Software FoundationLog4jversions up to 1.2.17
SAPNetWeaver Application Server ABAP

Exploit Intelligence

…and 311 more exploits

Timeline

  • Jun 28, 2021 PoC Published
  • Dec 10, 2021 PoC Published
  • Dec 11, 2021 PoC Published
  • Dec 13, 2021 PoC Published
  • Jun 7, 2022 PoC Published
  • Sep 16, 2022 PoC Published
  • Nov 21, 2023 PoC Published
  • Dec 8, 2023 PoC Published
  • Dec 11, 2023 PoC Published
  • Mar 1, 2024 PoC Published
  • Apr 5, 2024 PoC Published
  • Jul 17, 2024 PoC Published

References

…and 97 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›