

Rewterz Threat Advisory – Multiple F5 Products Vulnerabilities
February 15, 2024
Rewterz Threat Alert – Bumblebee Malware Resurfaces to Target US Organizations in Phishing Attacks – Active IOCs
February 15, 2024
Rewterz Threat Advisory – Multiple F5 Products Vulnerabilities
February 15, 2024
Rewterz Threat Alert – Bumblebee Malware Resurfaces to Target US Organizations in Phishing Attacks – Active IOCs
February 15, 2024Severity
Medium
Analysis Summary
CVE-2024-24739 CVSS: 6.3
SAP Bank Account Management could allow a remote authenticated attacker to gain elevated privileges on the system, caused by improper authorization validation. By sending a specially crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges.
CVE-2024-22130 CVSS: 7.6
SAP CRM is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote authenticated attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim’s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
CVE-2024-24740 CVSS: 5.3
SAP NetWeaver AS ABAP could allow a remote attacker to obtain sensitive information, caused by improper access control. By sending a specially crafted request, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.
CVE-2024-24741 CVSS: 4.3
SAP could allow a remote authenticated attacker to obtain sensitive information, caused by improper authorization validation. By sending a specially crafted request, an attacker could exploit this vulnerability to obtain sensitive information, and use this information to launch further attacks against the affected system.
CVE-2024-24742 CVSS: 4.1
SAP CRM is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote authenticated attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim’s Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
CVE-2024-22126 CVSS: 8.8
SAP NetWeaver AS Java is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially crafted URL to execute script in a victim’s Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
CVE-2024-25643 CVSS: 4.3
SAP Fiori app could allow a remote authenticated attacker to gain elevated privileges on the system, caused by improper authorization validation. By sending a specially crafted request, an authenticated attacker could exploit this vulnerability to gain elevated privileges.
CVE-2024-24743 CVSS: 8.6
SAP NetWeaver AS Java could allow a remote attacker to obtain sensitive information, caused by improper handling of XML external entity (XXE) declarations. By sending a specially crafted XML content, a remote attacker could exploit this vulnerability to read arbitrary files on the server.
CVE-2024-22128 CVSS: 4.7
SAP NetWeaver Business Client for HTML is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially crafted URL to execute script in a victim’s Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim’s cookie-based authentication credentials.
CVE-2024-22131 CVSS: 9.1
SAP ABA could allow a remote authenticated attacker to bypass security restrictions, caused by a code injection vulnerability in an exposed vulnerable interface. By leveraging the vulnerable interface to invoke an application function, an attacker could exploit this vulnerability to perform actions which they would not normally be permitted to perform, including reading or modifying any user or business data or make the entire system unavailable.
Impact
- Privilege Escalation
- Cross-Site Scripting
- Information Disclosure
- Security Bypass
Indicators Of Compromise
CVE
- CVE-2024-20726
- CVE-2024-20727
- CVE-2024-20728
- CVE-2024-20729
- CVE-2024-20730
- CVE-2024-20731
Affected Vendors
Siemens
Affected Products
- SAP NetWeaver AS Java 7.50
- SAP NetWeaver AS ABAP KERNEL 7.53
- SAP NetWeaver AS ABAP KERNEL 7.77
- SAP NetWeaver AS ABAP KERNEL 7.85
- SAP NetWeaver AS ABAP KERNEL 7.89
- SAP NetWeaver AS ABAP KERNEL 7.54
- SAP NetWeaver AS ABAP KERNEL 7.93
- SAP NetWeaver AS ABAP KERNEL 7.94
- SAP Bank Account Management SAP_FIN 618
- SAP Bank Account Management SAP_FIN 730
- SAP Bank Account Management S4CORE 100
- SAP Bank Account Management S4CORE 101
- SAP CRM S4FND 102
- SAP CRM S4FND 103
- SAP CRM S4FND 104
- SAP CRM S4FND 105
- SAP CRM S4FND 106
- SAP CRM S4FND 107
- SAP CRM WEBCUIF 700
- SAP CRM WEBCUIF 701
- SAP CRM WEBCUIF 731
- SAP CRM WEBCUIF 730
- SAP CRM WEBCUIF 746
- SAP CRM WEBCUIF 747
- SAP CRM WEBCUIF 748
- SAP CRM WEBCUIF 800
- SAP CRM 108
- SAP NetWeaver AS ABAP KRNL64UC 7.53
- SAP Master Data Governance Material 618
- SAP Master Data Governance Material 619
- SAP Master Data Governance Material 620
- SAP Master Data Governance Material 621
- SAP Master Data Governance Material 622
- SAP Master Data Governance Material 800
- SAP Master Data Governance Material 801
- SAP Master Data Governance Material 802
- SAP Master Data Governance Material 803
- SAP Master Data Governance Material 804
- SAP Fiori app 605
- SAP NetWeaver Business Client for HTML SAP_UI 754
- SAP NetWeaver Business Client for HTML SAP_UI 755
- SAP NetWeaver Business Client for HTML SAP_UI 756
- SAP NetWeaver Business Client for HTML SAP_UI 757
- SAP NetWeaver Business Client for HTML SAP_UI 758
- SAP NetWeaver Business Client for HTML SAP_BASIS 700
- SAP NetWeaver Business Client for HTML SAP_BASIS 701
- SAP NetWeaver Business Client for HTML SAP_BASIS 702
- SAP NetWeaver Business Client for HTML SAP_BASIS 731
- SAP ABA 700
- SAP ABA 701
- SAP ABA 702
- SAP ABA 731
- SAP ABA 740
- SAP ABA 750
- SAP ABA 751
- SAP ABA 752
- SAP ABA 75C
- SAP ABA 75I
Remediation
Current SAP customers should refer to SAP Security Document for patch information, available from the SAP Website (login required).