CVE-2024-54198: Information Disclosure vulnerability through Remote Function Call (RFC) in SAP NetWeaver Application Server ABAP

8.5 CVSS

Description

In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can be used to expose credentials for a remote service. These credentials can then be further exploited to completely compromise the remote service, potentially resulting in a significant impact on the confidentiality, integrity, and availability of the application.

Classification

CVE ID: CVE-2024-54198

CVSS Base Severity: HIGH

CVSS Base Score: 8.5

Affected Products

Vendor: SAP_SE

Product: SAP NetWeaver Application Server ABAP

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.44% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://me.sap.com/notes/3469791
https://url.sap/sapsecuritypatchday

Timeline