Elements of PDCE does not perform necessary
authorization checks for an authenticated user, resulting in escalation of
privileges.
This
allows an attacker to read sensitive information causing high impact on the
confidentiality of the application.
References
Link | Resource |
---|---|
https://me.sap.com/notes/3483344 | Permissions Required |
https://url.sap/sapsecuritypatchday | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
29 Aug 2024, 19:25
Type | Values Removed | Values Added |
---|---|---|
References | () https://me.sap.com/notes/3483344 - Permissions Required | |
References | () https://url.sap/sapsecuritypatchday - Vendor Advisory | |
First Time |
Sap s4core
Sap Sap s4coreop |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
CPE | cpe:2.3:a:sap:s4coreop:104:*:*:*:*:*:*:* cpe:2.3:a:sap:s4coreop:107:*:*:*:*:*:*:* cpe:2.3:a:sap:s4coreop:108:*:*:*:*:*:*:* cpe:2.3:a:sap:s4coreop:106:*:*:*:*:*:*:* cpe:2.3:a:sap:s4core:102:*:*:*:*:*:*:* cpe:2.3:a:sap:s4core:103:*:*:*:*:*:*:* cpe:2.3:a:sap:s4coreop:105:*:*:*:*:*:*:* |
09 Jul 2024, 18:19
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
09 Jul 2024, 04:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-09 04:15
Updated : 2024-08-29 19:25
NVD link : CVE-2024-39592
Mitre link : CVE-2024-39592
CVE.ORG link : CVE-2024-39592
JSON object : View
Products Affected
sap
- s4core
- s4coreop
CWE
CWE-862
Missing Authorization