SAP NetWeaver AS Java (CAF - Guided Procedures) - version 7.50, allows an unauthenticated attacker to submit a malicious request with a crafted XML file over the network, which when parsed will enable him to access sensitive files and data but not modify them. There are expansion limits in place so that availability is not affected.
Use CWE-611, Sap vendor hub and Netweaver Application Server Java product page to widen CVE-2024-24743 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-40309, CVE-2024-22127 and CVE-2024-34688 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 13th, 2026.