CVE-2024-45283 describes a sensitive information disclosure vulnerability in SAP NetWeaver AS for Java. An authorized attacker can exploit this flaw during RFC destination creation to obtain usernames and passwords. This medium-severity vulnerability (CVSS 6.0) requires high privileges and local access, allowing an attacker to read sensitive data but not modify or delete it. There is currently no public exploit code, active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| SAP SE | SAP NetWeaver AS For Java (Destination Service) | 7.50CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.