CVE-2024-41734: SAP NetWeaver Application Server Abap

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Due to missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform, an authenticated attacker could call an underlying transaction, which leads to disclosure of user related information. There is no impact on integrity or availability.

Affected products

  • SAP NetWeaver Application Server Abap: version sap_basis_700 only; version sap_basis_701 only; version sap_basis_702 only; version sap_basis_731 only; version sap_basis_740 only; version sap_basis_750 only; …

Published 2024-08-13. Last modified 2026-06-17.