CVE-2024-47586: SAP NetWeaver Abap Application Server

Medium severity, CVSS 5.3. EPSS: 3.5% chance of exploitation in the next 30 days.

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously crafted http request which could cause a null pointer dereference in the kernel. This dereference will result in the system crashing and rebooting, causing the system to be temporarily unavailable. There is no impact on Confidentiality or Integrity.

Affected products

  • SAP NetWeaver Abap Application Server: version 7.22EXT only; version 7.53 only; version 8.04 only; version 7.54 only; version 7.77 only; version 7.89 only; …
  • SAP SE SAP NetWeaver Application Server For Abap And Abap Platform: version 7.22EXT only; version 7.53 only; version 8.04 only; version 7.54 only; version 7.77 only; version 7.89 only; …

Published 2024-11-12. Last modified 2026-06-17.