CVE-2024-22124
MEDIUMDescription
Under certain conditions, Internet Communication Manager (ICM) or SAP Web Dispatcher - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, KRNL64NUC 7.22, KRNL64NUC 7.22_EXT, WEBDISP 7.22_EXT, WEBDISP 7.53, WEBDISP 7.54, could allow an attacker to access information which would otherwise be restricted causing high impact on confidentiality.
Is your site exposed to CVE-2024-22124?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| sap | netweaver |
| sap | netweaver |
| sap | netweaver |
| sap | netweaver |
| sap | netweaver |
| sap | netweaver |
| sap | netweaver |
| sap | netweaver |
| sap | netweaver |
| sap | netweaver |
References
Frequently Asked Questions
What is CVE-2024-22124? +
How severe is CVE-2024-22124? +
What products are affected by CVE-2024-22124? +
How do I check if I'm vulnerable to CVE-2024-22124? +
Related Vulnerabilities
Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere …
A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs …
An Exposure of Sensitive System Information to an Unauthorized Control Sphere and Initialization of a Resource with an Insecure Default …
SES safely executes third-party JavaScript 'strict' mode programs in compartments that have no excess authority in their global scope. Prior …
The affected products could allow an unauthenticated attacker to access system information that could enable further access to sensitive files …
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in OpenText Advanced Authentication allows Information Elicitation. The vulnerability …