CVE-2024-24743
CVSS 3.1 Score 8.6 of 10 (high)
Details
Published Feb 13, 2024
CWE ID 611
Summary
CVE-2024-24743 is a vulnerability affecting SAP NetWeaver AS Java (CAF - Guided Procedures) version 7.50. An unauthenticated attacker can exploit this issue by submitting a specially crafted XML file over the network. Upon parsing, the attacker gains access to sensitive files and data but is unable to modify them. The vulnerability does not pose a threat to system availability due to expansion limits in place.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.