CVE-2024-24743
SAP NetWeaver Application Server Java vulnerability analysis and mitigation

Overview

SAP NetWeaver AS Java (CAF - Guided Procedures) version 7.50 contains a vulnerability that was discovered and assigned CVE-2024-24743. The vulnerability was initially recorded on January 29, 2024, affecting the Guided Procedures component of SAP NetWeaver Application Server Java (CVE Details).

Technical details

The vulnerability allows an unauthenticated attacker to submit malicious requests containing crafted XML files over the network. When these files are parsed by the system, they can enable access to sensitive files and data. However, the vulnerability has built-in expansion limits that prevent availability impacts, and the attacker cannot modify the accessed files (CVE Details).

Impact

The primary impact of this vulnerability is the potential unauthorized access to sensitive files and data within the SAP NetWeaver AS Java system. While the attacker can read sensitive information, the vulnerability does not allow for modification of the accessed files (CERT-FR).

Mitigation and workarounds

SAP has addressed this vulnerability through their security update process. Users are advised to refer to SAP Security Note 3426111 for detailed mitigation instructions (CERT-FR).

Additional resources


SourceThis report was generated using AI

Related SAP NetWeaver Application Server Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-42944CRITICAL10
  • SAP NetWeaver Application Server JavaSAP NetWeaver Application Server Java
  • cpe:2.3:a:sap:netweaver_application_server_java
NoYesSep 09, 2025
CVE-2024-47578CRITICAL9.1
  • SAP NetWeaver Application Server JavaSAP NetWeaver Application Server Java
  • cpe:2.3:a:sap:netweaver_application_server_java
NoYesDec 10, 2024
CVE-2024-34688HIGH7.5
  • SAP NetWeaver Application Server JavaSAP NetWeaver Application Server Java
  • cpe:2.3:a:sap:netweaver_application_server_java
NoNoJun 11, 2024
CVE-2025-42926MEDIUM5.3
  • SAP NetWeaver Application Server JavaSAP NetWeaver Application Server Java
  • cpe:2.3:a:sap:netweaver_application_server_java
NoYesSep 09, 2025
CVE-2024-47592MEDIUM5.3
  • SAP NetWeaver Application Server JavaSAP NetWeaver Application Server Java
  • cpe:2.3:a:sap:netweaver_application_server_java
NoYesNov 12, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management