Vulnerabilities > CVE-2024-27898 - Unspecified vulnerability in SAP Netweaver 7.5
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
SAP NetWeaver application, due to insufficient input validation, allows an attacker to send a crafted request from a vulnerable web application targeting internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. Thus, having a low impact on confidentiality.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |