# CVE-2024-54198

## Summary

- **CVE ID:** CVE-2024-54198
- **Severity:** HIGH
- **CVSS Score:** 8.5 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-914
- **Published:** Dec 10, 2024
- **Last Modified:** Mar 13, 2026

## Description

In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can be used to expose credentials for a remote service. These credentials can then be further exploited to completely compromise the remote service, potentially resulting in a significant impact on the confidentiality, integrity, and availability of the application.

## Affected Products

- SAP_SE — SAP NetWeaver Application Server ABAP (KRNL64NUC 7.22)
- SAP_SE — SAP NetWeaver Application Server ABAP (7.22EXT)
- SAP_SE — SAP NetWeaver Application Server ABAP (KRNL64UC 7.22)
- SAP_SE — SAP NetWeaver Application Server ABAP (7.53)
- SAP_SE — SAP NetWeaver Application Server ABAP (KERNEL 7.22)
- SAP_SE — SAP NetWeaver Application Server ABAP (7.54)
- SAP_SE — SAP NetWeaver Application Server ABAP (7.77)
- SAP_SE — SAP NetWeaver Application Server ABAP (7.89)
- SAP_SE — SAP NetWeaver Application Server ABAP (7.93)

## References

- [CNA](https://me.sap.com/notes/3469791)
- [CNA](https://url.sap/sapsecuritypatchday)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.61%
- **EPSS Percentile:** 46.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._