VDB
GCVE-110-NCSC-2024-472
GCVE-110-NCSC-2024-472
Advisory PublishedCVSS 5.3/10
SAP heeft kwetsbaarheden verholpen in SAP NetWeaver, ABAP, Web Dispatcher, Business Objects, HCM en Commerce Cloud.
Weaknesses (CWE)
CWE-497Exposure of Sensitive System Information to an Unauthorized Control SphereCWE-427Uncontrolled Search Path ElementCWE-319Cleartext Transmission of Sensitive InformationCWE-918Server-Side Request Forgery (SSRF)CWE-538Insertion of Sensitive Information into Externally-Accessible File or DirectoryCWE-862Missing AuthorizationCWE-611Improper Restriction of XML External Entity ReferenceCWE-476NULL Pointer DereferenceCWE-791Incomplete Filtering of Special ElementsCWE-914Improper Control of Dynamically-Identified Variables
Risk Scores
CVSS 3.1
5.3/10
Medium · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| sap_se | sap_businessobjects_business_intelligence_platform | — | — |
| sap_se | sap_product_lifecycle_costing | — | — |
| sap | web_dispatcher | — | — |
| sap_se | sap_web_dispatcher | — | — |
| sap_se | sap_commerce_cloud | — | — |
| sap_se | sap_hcm | — | — |
| sap_se | sap_netweaver_as_java | — | — |
| sap_se | sap_netweaver_administrator_system_overview_ | — | — |
| sap | netweaver_as_for_java | — | — |
| sap_se | sap_netweaver_as_for_java__adobe_document_services_ | — | — |
| sap_se | sap_netweaver_application_server_for_abap_and_abap_platform | — | — |
| sap | netweaver_application_server_abap | — | — |
| sap_se | sap_netweaver_application_server_abap | — | — |
| sap | sap | — | — |
| sap | netweaver_abap_application_server | — | — |
| sap | commerce_cloud | — | — |
Browse GCVE Records
74,299 records in the GCVE database · Updated July 22, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.