mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-30 18:56:19 +00:00
31 lines
2.0 KiB
Markdown
31 lines
2.0 KiB
Markdown
### [CVE-2024-39598](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-39598)
|
|

|
|

|
|

|
|

|
|

|
|

|
|

|
|

|
|

|
|

|
|

|
|

|
|

|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
SAP CRM (WebClient UI Framework) allows anauthenticated attacker to enumerate accessible HTTP endpoints in the internalnetwork by specially crafting HTTP requests. On successful exploitation thiscan result in information disclosure. It has no impact on integrity andavailability of the application.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
No PoCs from references.
|
|
|
|
#### Github
|
|
- https://github.com/fkie-cad/nvd-json-data-feeds
|
|
|