CVE-2024-37171

Severity CVSS v4.0:
Pending analysis
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
09/07/2024
Last modified:
09/09/2024

Description

SAP Transportation Management (Collaboration<br /> Portal) allows an attacker with non-administrative privileges to send a crafted<br /> request from a vulnerable web application. This will trigger the application<br /> handler to send a request to an unintended service, which may reveal<br /> information about that service. The information obtained could be used to<br /> target internal systems behind firewalls that are normally inaccessible to an<br /> attacker from the external network, resulting in a Server-Side Request Forgery<br /> vulnerability. There is no effect on integrity or availability of the<br /> application.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:saptmui:140:*:*:*:*:*:*:*
cpe:2.3:a:sap:saptmui:150:*:*:*:*:*:*:*
cpe:2.3:a:sap:saptmui:160:*:*:*:*:*:*:*
cpe:2.3:a:sap:saptmui:170:*:*:*:*:*:*:*
cpe:2.3:a:sap:transportation_management:-:*:*:*:*:*:*:*