CVE-2024-41737

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
13/08/2024
Last modified:
12/09/2024

Description

SAP CRM ABAP (Insights<br /> Management) allows an authenticated attacker to enumerate HTTP endpoints in the<br /> internal network by specially crafting HTTP requests. On successful<br /> exploitation this can result in information disclosure. It has no impact on<br /> integrity and availability of the application.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:crm_abap_insights_management:bbpcrm_700:*:*:*:*:*:*:*
cpe:2.3:a:sap:crm_abap_insights_management:bbpcrm_701:*:*:*:*:*:*:*
cpe:2.3:a:sap:crm_abap_insights_management:bbpcrm_702:*:*:*:*:*:*:*
cpe:2.3:a:sap:crm_abap_insights_management:bbpcrm_712:*:*:*:*:*:*:*
cpe:2.3:a:sap:crm_abap_insights_management:bbpcrm_713:*:*:*:*:*:*:*
cpe:2.3:a:sap:crm_abap_insights_management:bbpcrm_714:*:*:*:*:*:*:*