VYPR
Medium severity5.4NVD Advisory· Published Sep 10, 2024· Updated Apr 15, 2026

CVE-2024-44117

CVE-2024-44117

Description

The RFC enabled function module allows a low privileged user to perform various actions, such as modifying the URLs of any user's favourite nodes and workbook ID. There is low impact on integrity and availability of the application.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A low-privileged user can exploit an RFC-enabled function module to modify URLs of any user's favorite nodes and workbook IDs, impacting integrity and availability.

Vulnerability

Overview CVE-2024-44117 describes a flaw in an RFC-enabled function module within SAP applications. The module fails to properly enforce authorization checks, allowing a low-privileged user to perform actions that should be restricted. Specifically, the attacker can modify the URLs of any user's favorite nodes and workbook IDs [1].

Exploitation

Exploitation requires only low privileges and network access to the RFC interface. No authentication bypass is needed; the attacker simply invokes the vulnerable function module with crafted parameters. The attack surface is limited to users who have access to RFC calls, but the lack of proper authorization means any such user can target arbitrary other users' data.

Impact

Successful exploitation results in low integrity and availability impact. The attacker can alter URLs that other users rely on, potentially redirecting them to malicious content or causing denial of service by corrupting workbook IDs. The confidentiality of data is not directly affected.

Mitigation

SAP has addressed this vulnerability in its Security Patch Day on September 10, 2024. Administrators should apply the relevant SAP Security Note as soon as possible. No workarounds are documented, so patching is the recommended course of action [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.