CVE-2024-41737: SAP CRM Abap Insights Management

Medium severity, CVSS 5.0. EPSS: 0.3% chance of exploitation in the next 30 days.

SAP CRM ABAP (Insights Management) allows an authenticated attacker to enumerate HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in information disclosure. It has no impact on integrity and availability of the application.

Affected products

  • SAP CRM Abap Insights Management: version bbpcrm_700 only; version bbpcrm_701 only; version bbpcrm_702 only; version bbpcrm_712 only; version bbpcrm_713 only; version bbpcrm_714 only

Published 2024-08-13. Last modified 2026-06-17.