CVE-2024-54198: SAP SE SAP NetWeaver Application Server Abap

High severity, CVSS 8.5. EPSS: 0.6% chance of exploitation in the next 30 days.

In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can be used to expose credentials for a remote service. These credentials can then be further exploited to completely compromise the remote service, potentially resulting in a significant impact on the confidentiality, integrity, and availability of the application.

Affected products

  • SAP SE SAP NetWeaver Application Server Abap: version 7.22EXT only; version 7.53 only; version 7.54 only; version 7.77 only; version 7.89 only; version 7.93 only

Published 2024-12-10. Last modified 2026-06-17.