Medium severity5.3NVD Advisory· Published Apr 9, 2024· Updated Jun 17, 2026
CVE-2024-27898
CVE-2024-27898
Description
SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targeting internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. Thus, having a low impact on confidentiality.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- support.sap.com/en/my-support/knowledge-base/security-notes-news.htmlnvdVendor Advisory
- me.sap.com/notes/3425188nvdPermissions Required
News mentions
0No linked articles in our index yet.