CVE-2024-47585 is a privilege escalation vulnerability affecting SAP NetWeaver Application Server for ABAP and ABAP Platform. An authenticated attacker can exploit improper authorization checks to gain higher access levels, stemming from a single authorization being applied for both import and export functions. This vulnerability has a CVSS score of 4.3 (Medium), indicating a low impact on confidentiality and no impact on integrity or availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| SAP SE | SAP NetWeaver Application Server For ABAP And ABAP Platform | SAP_BASIS 740, SAP_BASIS 750CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.