#VU101372 Information disclosure in SAP NetWeaver AS ABAP - CVE-2024-54198
Published: December 10, 2024
SAP NetWeaver AS ABAP
SAP
Description
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote user can send a specially crafted RPC request to restricted destinations and expose credentials for a remote service and use the obtained credentials to compromise the affected service.