CVE-2024-37171
Last modified
CVE-2024-37171 is a medium-severity vulnerability rated 5/10 on the CVSS scale. SAP Transportation Management (Collaboration Portal) allows an attacker with non-administrative privileges to send a crafted request from a vulnerable web application. This will trigger the application handler to send a request to an unintended service, which may reveal information about that service. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
SAP Transportation Management (Collaboration Portal) allows an attacker with non-administrative privileges to send a crafted request from a vulnerable web application. This will trigger the application handler to send a request to an unintended service, which may reveal information about that service. The information obtained could be used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network, resulting in a Server-Side Request Forgery vulnerability. There is no effect on integrity or availability of the application.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Saptmui | 140 |
| Sap | Saptmui | 150 |
| Sap | Saptmui | 160 |
| Sap | Saptmui | 170 |
| Sap | Transportation Management | All versions |
References
- https://me.sap.com/notes/3469958Permissions Required
- https://url.sap/sapsecuritypatchdayVendor Advisory
- https://me.sap.com/notes/3469958Permissions Required
- https://url.sap/sapsecuritypatchdayVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-37171?
How severe is CVE-2024-37171?
How do I fix CVE-2024-37171?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-37165Discourse is an open source discussion platform. Prior to 3.…6.1
- CVE-2024-37166ghtml is software that uses tagged templates for template en…8.9
- CVE-2024-37167Tuleap is an Open Source Suite to improve management of soft…4.3
- CVE-2024-37168@grpc/grps-js implements the core functionality of gRPC pure…5.3
- CVE-2024-37169@jmondi/url-to-png is a self-hosted URL to PNG utility. Vers…5.3
- CVE-2024-3717The Drag and Drop Multiple File Upload – Contact Form 7 plug…7.5
- CVE-2024-37172SAP S/4HANA Finance (Advanced Payment Management) does not p…5.4
- CVE-2024-37173Due to insufficient input validation, SAP CRM WebClient UI…6.1
- CVE-2024-37174Custom CSS support option in SAP CRM WebClient UI does not s…6.1
- CVE-2024-37175SAP CRM WebClient does not perform necessary authorization c…6.5
- CVE-2024-37176SAP BW/4HANA Transformation and Data Transfer Process (DTP) …5.4
- CVE-2024-37177SAP Financial Consolidation allows data to enter a Web appli…8.1
Are you affected by CVE-2024-37171?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
