High severity8.6NVD Advisory· Published Feb 13, 2024· Updated Jun 17, 2026
CVE-2024-24743
CVE-2024-24743
Description
SAP NetWeaver AS Java (CAF - Guided Procedures) - version 7.50, allows an unauthenticated attacker to submit a malicious request with a crafted XML file over the network, which when parsed will enable him to access sensitive files and data but not modify them. There are expansion limits in place so that availability is not affected.
Affected products
3- cpe:2.3:a:sap:netweaver_application_server_java:7.50:*:*:*:*:*:*:*
- Range: = 7.50
- Range: 7.50
Patches
Vulnerability mechanics
References
2- www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.htmlnvdVendor Advisory
- me.sap.com/notes/3426111nvdPermissions Required
News mentions
0No linked articles in our index yet.