CVE-2024-37171
Severity CVSS v4.0:
Pending analysis
Type:
CWE-918
Server-Side Request Forgery (SSRF)
Publication date:
09/07/2024
Last modified:
09/09/2024
Description
SAP Transportation Management (Collaboration<br />
Portal) allows an attacker with non-administrative privileges to send a crafted<br />
request from a vulnerable web application. This will trigger the application<br />
handler to send a request to an unintended service, which may reveal<br />
information about that service. The information obtained could be used to<br />
target internal systems behind firewalls that are normally inaccessible to an<br />
attacker from the external network, resulting in a Server-Side Request Forgery<br />
vulnerability. There is no effect on integrity or availability of the<br />
application.
Impact
Base Score 3.x
5.00
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sap:saptmui:140:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:saptmui:150:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:saptmui:160:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:saptmui:170:*:*:*:*:*:*:* | ||
| cpe:2.3:a:sap:transportation_management:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



