CVE-2024-24743

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Feb 13, 2024
CWE ID 611

Summary

CVE-2024-24743 is a vulnerability affecting SAP NetWeaver AS Java (CAF - Guided Procedures) version 7.50. An unauthenticated attacker can exploit this issue by submitting a specially crafted XML file over the network. Upon parsing, the attacker gains access to sensitive files and data but is unable to modify them. The vulnerability does not pose a threat to system availability due to expansion limits in place.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share