Medium severity4.3NVD Advisory· Published Aug 13, 2024· Updated Jun 17, 2026
CVE-2024-42377
CVE-2024-42377
Description
SAP shared service framework allows an authenticated non-administrative user to call a remote-enabled function, which will allow them to insert value entries into a non-sensitive table, causing low impact on integrity of the application
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7SAP_BS_FND 702+ 6 more
- (no CPE)range: SAP_BS_FND 702
- (no CPE)
- cpe:2.3:a:sap:shared_service_framework:sap_bs_fnd_702:*:*:*:*:*:*:*
- cpe:2.3:a:sap:shared_service_framework:sap_bs_fnd_731:*:*:*:*:*:*:*
- cpe:2.3:a:sap:shared_service_framework:sap_bs_fnd_746:*:*:*:*:*:*:*
- cpe:2.3:a:sap:shared_service_framework:sap_bs_fnd_747:*:*:*:*:*:*:*
- cpe:2.3:a:sap:shared_service_framework:sap_bs_fnd_748:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- url.sap/sapsecuritypatchdaynvdVendor Advisory
- me.sap.com/notes/3474590nvdPermissions Required
News mentions
0No linked articles in our index yet.