VDB

CISA-2024-42377

CISA-2024-42377 PUBLISHED CVSS 4.3 MEDIUM

Reported by sap · Published August 13, 2024

SAP shared service framework allows an authenticated non-administrative user to call a remote-enabled function, which will allow them to insert value entries into a non-sensitive table, causing low impact on integrity of the application

Risk Scores

CVSS 3.1
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Affected Products

VendorProductVersions
SAP_SESAP Shared Service FrameworkSAP_BS_FND 702, 731, 746
SAP_SESAP Shared Service FrameworkSAP_BS_FND 702, 731, 746

Timeline

  • Aug 13, 2024 CVE Published
  • Aug 13, 2024 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›