CVE-2024-44117
Description
The RFC enabled function module allows a low privileged user to perform various actions, such as modifying the URLs of any user's favourite nodes and workbook ID. There is low impact on integrity and availability of the application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A low-privileged user can exploit an RFC-enabled function module to modify URLs of any user's favorite nodes and workbook IDs, impacting integrity and availability.
Vulnerability
Overview CVE-2024-44117 describes a flaw in an RFC-enabled function module within SAP applications. The module fails to properly enforce authorization checks, allowing a low-privileged user to perform actions that should be restricted. Specifically, the attacker can modify the URLs of any user's favorite nodes and workbook IDs [1].
Exploitation
Exploitation requires only low privileges and network access to the RFC interface. No authentication bypass is needed; the attacker simply invokes the vulnerable function module with crafted parameters. The attack surface is limited to users who have access to RFC calls, but the lack of proper authorization means any such user can target arbitrary other users' data.
Impact
Successful exploitation results in low integrity and availability impact. The attacker can alter URLs that other users rely on, potentially redirecting them to malicious content or causing denial of service by corrupting workbook IDs. The confidentiality of data is not directly affected.
Mitigation
SAP has addressed this vulnerability in its Security Patch Day on September 10, 2024. Administrators should apply the relevant SAP Security Note as soon as possible. No workarounds are documented, so patching is the recommended course of action [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.