Medium severity4.1NVD Advisory· Published Jul 9, 2024· Updated Jun 17, 2026
CVE-2024-37180
CVE-2024-37180
Description
Under certain conditions SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker to access remote-enabled function module with no further authorization which would otherwise be restricted, the function can be used to read non-sensitive information with low impact on confidentiality of the application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
16cpe:2.3:a:sap:sap_basis:700:*:*:*:*:*:*:*+ 13 more
- cpe:2.3:a:sap:sap_basis:700:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:701:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:702:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:731:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:740:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:750:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:751:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:752:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:753:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:754:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:755:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:756:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:757:*:*:*:*:*:*:*
- cpe:2.3:a:sap:sap_basis:758:*:*:*:*:*:*:*
- Range: SAP_BASIS 700
Patches
Vulnerability mechanics
References
2- url.sap/sapsecuritypatchdaynvdPatch
- me.sap.com/notes/3454858nvdPermissions Required
News mentions
0No linked articles in our index yet.