CVE-2024-21737
CVSS V2 None
CVSS V3 None
Description
In SAP Application Interface Framework File Adapter - version 702, a high privilege user can use a function module to traverse through various layers and execute OS commands directly. By this, such user can control the behaviour of the application. This leads to considerable impact on confidentiality, integrity and availability.
Overview
- CVE ID
- CVE-2024-21737
- Assigner
- sap
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-01-09T01:18:19.305Z
- Last Modified Date
- 2024-01-09T01:18:19.305Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://me.sap.com/notes/3411869 | |
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-21737 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21737 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 15:05:33 | Added to TrackCVE |