CVE-2024-42377: SAP Shared Service Framework

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

SAP shared service framework allows an authenticated non-administrative user to call a remote-enabled function, which will allow them to insert value entries into a non-sensitive table, causing low impact on integrity of the application

Affected products

  • SAP Shared Service Framework: version sap_bs_fnd_702 only; version sap_bs_fnd_731 only; version sap_bs_fnd_746 only; version sap_bs_fnd_747 only; version sap_bs_fnd_748 only

Published 2024-08-13. Last modified 2026-06-17.