VDB

GCVE-110-NCSC-2024-472

GCVE-110-NCSC-2024-472
Advisory PublishedCVSS 5.3/10
Vulnetix · Advisory published December 10, 2024
SAP heeft kwetsbaarheden verholpen in SAP NetWeaver, ABAP, Web Dispatcher, Business Objects, HCM en Commerce Cloud.

Weaknesses (CWE)

CWE-497Exposure of Sensitive System Information to an Unauthorized Control SphereCWE-427Uncontrolled Search Path ElementCWE-319Cleartext Transmission of Sensitive InformationCWE-918Server-Side Request Forgery (SSRF)CWE-538Insertion of Sensitive Information into Externally-Accessible File or DirectoryCWE-862Missing AuthorizationCWE-611Improper Restriction of XML External Entity ReferenceCWE-476NULL Pointer DereferenceCWE-791Incomplete Filtering of Special ElementsCWE-914Improper Control of Dynamically-Identified Variables

Risk Scores

CVSS 3.1
5.3/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected Products

VendorProductVersionsPlatforms
sap_sesap_businessobjects_business_intelligence_platform
sap_sesap_product_lifecycle_costing
sapweb_dispatcher
sap_sesap_web_dispatcher
sap_sesap_commerce_cloud
sap_sesap_hcm
sap_sesap_netweaver_as_java
sap_sesap_netweaver_administrator_system_overview_
sapnetweaver_as_for_java
sap_sesap_netweaver_as_for_java__adobe_document_services_
sap_sesap_netweaver_application_server_for_abap_and_abap_platform
sapnetweaver_application_server_abap
sap_sesap_netweaver_application_server_abap
sapsap
sapnetweaver_abap_application_server
sapcommerce_cloud

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

74,299 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›