Elements of PDCE does not perform necessary
authorization checks for an authenticated user, resulting in escalation of
privileges.
This
allows an attacker to read sensitive information causing high impact on the
confidentiality of the application.
References
Link | Resource |
---|---|
https://url.sap/sapsecuritypatchday | Vendor Advisory |
https://me.sap.com/notes/3483344 | Permissions Required |
Configurations
Configuration 1 (hide)
|
History
29 Aug 2024, 19:25
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:sap:s4coreop:107:*:*:*:*:*:*:* cpe:2.3:a:sap:s4coreop:106:*:*:*:*:*:*:* cpe:2.3:a:sap:s4core:102:*:*:*:*:*:*:* cpe:2.3:a:sap:s4coreop:104:*:*:*:*:*:*:* cpe:2.3:a:sap:s4coreop:105:*:*:*:*:*:*:* cpe:2.3:a:sap:s4coreop:108:*:*:*:*:*:*:* cpe:2.3:a:sap:s4core:103:*:*:*:*:*:*:* |
|
First Time |
Sap
Sap s4core Sap s4coreop |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
References | () https://me.sap.com/notes/3483344 - Permissions Required | |
References | () https://url.sap/sapsecuritypatchday - Vendor Advisory |
09 Jul 2024, 04:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-09 04:15
Updated : 2024-08-29 19:25
NVD link : CVE-2024-39592
Mitre link : CVE-2024-39592
JSON object : View
Products Affected
sap
- s4coreop
- s4core
CWE
CWE-862
Missing Authorization