VDB

GCVE-VVD-NCSC-2024-378

GCVE-VVD-NCSC-2024-378
Advisory PublishedCVSS 5.9/10
Vulnetix · Advisory published September 19, 2024
SAP heeft kwetsbaarheden verholpen in diverse producten, zoals SAP, Business Warehouse, NetWeaver, HANA, Business Objects en Commerce.

Weaknesses (CWE)

CWE-325Missing Cryptographic StepCWE-862Missing AuthorizationCWE-359Exposure of Private Personal Information to an Unauthorized ActorCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-863Incorrect AuthorizationCWE-213Exposure of Sensitive Information Due to Incompatible PoliciesCWE-426Untrusted Search PathCWE-256Plaintext Storage of a Password

Risk Scores

CVSS 3.1
5.9/10
Medium · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersionsPlatforms
sapsap
sapcommerce_cloud
sap_sesap_netweaver_application_server_for_abap_and_abap_platform
sapnetweaver_application_server_abap
sap_sesap_netweaver_bw__bex_analyzer_
sap_sesap_s_4hana_eprocurement
sap_sesap_for_oil___gas
sapoil_\%\/_gas
sap_sesap_business_warehouse__bex_analyzer_
sap_sesap_netweaver_enterprise_portal
sapnetweaver_enterprise_portal
sap_sesap_s_4_hana__statutory_reports_
sap_sesap_netweaver_application_server_for_abap__crm_blueprint_application_builder_panel_
sap_sesap_netweaver_as_java__logon_application_
sap_sesap_businessobjects_business_intelligence_platform
sapbusinessobjects_business_intelligence_platform
sap_sesap_netweaver_as_for_java__destination_service_
sapnetweaver_as_for_java
sap_sesap_student_life_cycle_management__slcm_
sapstudent_life_cycle_management
sap_sesap_production_and_revenue_accounting__tobin_interface_

Aliases

Transitive aliases

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›