Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
SAP’s June 11, 2024 Security Patch Day addressed three high-severity vulnerabilities across two SAP product areas: two cross-site scripting flaws in SAP Financial Consolidation and a denial-of-service flaw in SAP NetWeaver AS Java. SAP published 10 new security notes and updated three previously released notes.
The relevant remediation records are SAP Note 3457592 for Financial Consolidation and SAP Note 3460407 for NetWeaver AS Java. Administrators should verify their exact support-package and component levels in SAP for Me rather than relying only on the product name.
At a glance
| Product | SAP Note | CVE | Issue | Affected scope | SAP rating |
|---|---|---|---|---|---|
| SAP Financial Consolidation | 3457592 | CVE-2024-37177 | Cross-site scripting | FINANCE 1010 | High; CVSS 8.1 |
| SAP Financial Consolidation | 3457592 | CVE-2024-37178 | Cross-site scripting | FINANCE 1010 | High; CVSS 8.1 in SAP’s bulletin |
| SAP NetWeaver AS Java | 3460407 | CVE-2024-34688 | Denial of service | Meta Model Repository, MMR_SERVER 7.5 | High; CVSS 7.5 |
“Patches” here means SAP Security Notes and the associated correction or support-package processes, not necessarily one standalone installer.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteFinancial Consolidation: two XSS vulnerabilities
CVE-2024-37177
CVE-2024-37177 is a cross-site scripting vulnerability classified by NVD under CWE-79, improper neutralization of input during web-page generation. The published description indicates that untrusted input can reach a network-exposed web-application endpoint and alter website content, with potentially significant confidentiality and integrity consequences.
#1 Best Overall
Its published CVSS characteristics indicate network reachability, low attack complexity, no privileges required, and required user interaction. In practical terms, exploitation may depend on the particular endpoint, browser behavior, and whether a user views attacker-controlled content. XSS should not automatically be interpreted as remote code execution.
CVE-2024-37178
CVE-2024-37178 is a second XSS issue covered by SAP Note 3457592. It should not be treated as identical to CVE-2024-37177: NVD records a different attack profile, including a privileges-required condition and changed scope, with a distinct impact vector.
Rank #2
Both CVEs concern SAP Financial Consolidation, FINANCE 1010, but the public bulletin does not provide a complete support-package matrix. Organizations must use the current version of SAP Note 3457592 in SAP for Me to determine whether their installation is affected and which correction applies.
NetWeaver AS Java: denial-of-service risk
SAP Note 3460407 addresses CVE-2024-34688 in the Meta Model Repository component of SAP NetWeaver AS Java. The identified component is MMR_SERVER 7.5.
Rank #3
- Used Book in Good Condition
According to NVD’s record, the issue is associated with uncontrolled resource consumption, or CWE-400. Its published vector describes a network-accessible vulnerability that requires low attack complexity, no privileges, and no user interaction. The documented impact is high availability impact, with no confidentiality or integrity impact in the published vector.
A successful denial-of-service attack could interrupt application access, disrupt transactions, interfere with administration, or create incident-response work. The public description does not establish data theft, code execution, or server takeover.
Rank #4
What SAP administrators should do
- Inventory the landscape. Confirm whether SAP Financial Consolidation FINANCE 1010 is installed and whether NetWeaver AS Java includes MMR_SERVER 7.5. Record releases, support packages, component levels, and existing patch status.
- Open the SAP Notes. Review 3457592 and 3460407 in SAP for Me. Check the current note revision, prerequisites, correction instructions, affected support packages, and implementation status. SAP’s public bulletin intentionally contains less implementation detail than customer-facing notes.
- Assess reachability. Review whether the relevant web or repository services can be reached by corporate users, partners, VPN users, compromised internal hosts, or other semi-trusted networks. “Not exposed to the internet” does not mean “not reachable by an attacker.”
- Prioritize deployment. Treat Financial Consolidation as urgent where web endpoints are reachable by untrusted or semi-trusted users. Prioritize the NetWeaver correction where repository services cross untrusted network boundaries or where availability requirements are high.
- Test safely. Apply the correction in development or test first. Exercise login, reporting, consolidation workflows, scheduled jobs, integrations, Java services, and administrative functions. Check customizations, filters, and dependent systems.
- Deploy using SAP’s process. Follow the applicable support-package, correction-instruction, transport, and restart requirements. Coordinate maintenance windows with Basis, application owners, and business stakeholders.
- Validate and monitor. Recheck component levels and note implementation status. Review application, HTTP, Java, and security logs for suspicious requests or availability anomalies. Document the change and any remaining exposure.
Mitigations and limitations
Patching is the preferred remedy because it provides a durable correction and creates clearer compliance evidence. A temporary mitigation may be useful during testing, a change freeze, or an operational dependency, but it reduces exposure without eliminating the vulnerability.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsPublic secondary coverage reports that SAP Note 3457592 includes a workaround or mitigation related to input encoding or application behavior. Because the exact instructions are in the authenticated SAP Note, administrators should not reproduce or adapt them from summaries alone.
Best Value
Secondary reporting also says no workaround was available for SAP Note 3460407’s NetWeaver denial-of-service issue. Confirm the current position directly in SAP for Me. Do not disable unrelated services or assume that generic network filtering is equivalent to SAP’s correction unless SAP’s note specifically supports that control for the organization’s architecture.
Why the date matters
This was a June 11, 2024 SAP security update, not a new disclosure in 2026. SAP Note 3460407 was later listed as updated during the August 2024 Patch Day, so administrators should use the current note revision and support matrix rather than the original June bulletin alone.
The June release contained 10 new security notes and three updates overall. The two product areas covered here account for three CVEs: two affecting Financial Consolidation and one affecting NetWeaver AS Java.
Quick Recap
Key qualifications
- SAP classified both notes as High, not Critical.
- Network reachability does not necessarily mean unrestricted public-internet exploitability.
- The two Financial Consolidation CVEs have different published authentication, interaction, and impact characteristics.
- The NetWeaver CVE is documented as an availability issue; the cited record does not establish data theft or code execution.
- NVD’s current exploitation status information should not be treated as proof that exploitation has never occurred.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

