CVE-2024-42372: SAP NetWeaver System Landscape Directory
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthorized user can read and modify some restricted global SLD configurations causing low impact on confidentiality and integrity of the application.
Affected products
- SAP NetWeaver System Landscape Directory: version 7.5 only
- SAP SE SAP NetWeaver As Java System Landscape Directory
Published 2024-11-12. Last modified 2026-06-17.