CVE-2024-41729: SAP SE SAP NetWeaver Bw Bex Analyzer

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Due to missing authorization checks, SAP BEx Analyzer allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker can enumerate information causing a limited impact on confidentiality of the application.

Affected products

  • SAP SE SAP NetWeaver Bw Bex Analyzer

Published 2024-09-10. Last modified 2026-06-17.