Логотип exploitDog
bind:CVE-2024-54197
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-54197

Количество 3

Количество 3

nvd логотип

CVE-2024-54197

около 1 года назад

SAP NetWeaver Administrator(System Overview) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in Server-Side Request Forgery (SSRF) which could have a low impact on integrity and confidentiality of data. It has no impact on availability of the application.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-rmp2-7p3x-qqg2

около 1 года назад

SAP NetWeaver Administrator(System Overview) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in Server-Side Request Forgery (SSRF) which could have a low impact on integrity and confidentiality of data. It has no impact on availability of the application.

CVSS3: 7.2
EPSS: Низкий
fstec логотип

BDU:2024-10995

около 1 года назад

Уязвимость программного обеспечения для администрирования SAP NetWeaver Administrator, связанная с недостаточной проверкой запросов на стороне сервера, позволяющая нарушителю осуществить SSRF-атаку

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-54197

SAP NetWeaver Administrator(System Overview) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in Server-Side Request Forgery (SSRF) which could have a low impact on integrity and confidentiality of data. It has no impact on availability of the application.

CVSS3: 7.2
0%
Низкий
около 1 года назад
github логотип
GHSA-rmp2-7p3x-qqg2

SAP NetWeaver Administrator(System Overview) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in Server-Side Request Forgery (SSRF) which could have a low impact on integrity and confidentiality of data. It has no impact on availability of the application.

CVSS3: 7.2
0%
Низкий
около 1 года назад
fstec логотип
BDU:2024-10995

Уязвимость программного обеспечения для администрирования SAP NetWeaver Administrator, связанная с недостаточной проверкой запросов на стороне сервера, позволяющая нарушителю осуществить SSRF-атаку

CVSS3: 7.2
0%
Низкий
около 1 года назад

Уязвимостей на страницу