cve/2024/CVE-2024-37171.md
2025-09-29 21:09:30 +02:00

1.4 KiB

CVE-2024-37171

Description

SAP Transportation Management (CollaborationPortal) allows an attacker with non-administrative privileges to send a craftedrequest from a vulnerable web application. This will trigger the applicationhandler to send a request to an unintended service, which may revealinformation about that service. The information obtained could be used totarget internal systems behind firewalls that are normally inaccessible to anattacker from the external network, resulting in a Server-Side Request Forgeryvulnerability. There is no effect on integrity or availability of theapplication.

POC

Reference

No PoCs from references.

Github