Логотип exploitDog
bind:CVE-2024-37171
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-37171

Количество 3

Количество 3

nvd логотип

CVE-2024-37171

больше 1 года назад

SAP Transportation Management (Collaboration Portal) allows an attacker with non-administrative privileges to send a crafted request from a vulnerable web application. This will trigger the application handler to send a request to an unintended service, which may reveal information about that service. The information obtained could be used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. There is no effect on integrity or availability of the application.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-c5r3-m97h-6m7r

больше 1 года назад

SAP Transportation Management (Collaboration Portal) allows an attacker with non-administrative privileges to send a crafted request from a vulnerable web application. This will trigger the application handler to send a request to an unintended service, which may reveal information about that service. The information obtained could be used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. There is no effect on integrity or availability of the application.

CVSS3: 5
EPSS: Низкий
fstec логотип

BDU:2025-00005

больше 1 года назад

Уязвимость компонента Collaboration Portal системы управления транспортой логистикой SAP Transportation Management (SAP TM), позволяющая нарушителю осуществить SSRF-атаку

CVSS3: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-37171

SAP Transportation Management (Collaboration Portal) allows an attacker with non-administrative privileges to send a crafted request from a vulnerable web application. This will trigger the application handler to send a request to an unintended service, which may reveal information about that service. The information obtained could be used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. There is no effect on integrity or availability of the application.

CVSS3: 5
0%
Низкий
больше 1 года назад
github логотип
GHSA-c5r3-m97h-6m7r

SAP Transportation Management (Collaboration Portal) allows an attacker with non-administrative privileges to send a crafted request from a vulnerable web application. This will trigger the application handler to send a request to an unintended service, which may reveal information about that service. The information obtained could be used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. There is no effect on integrity or availability of the application.

CVSS3: 5
0%
Низкий
больше 1 года назад
fstec логотип
BDU:2025-00005

Уязвимость компонента Collaboration Portal системы управления транспортой логистикой SAP Transportation Management (SAP TM), позволяющая нарушителю осуществить SSRF-атаку

CVSS3: 5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу