CVE-2023-24524

SAP S/4 HANA Map Treasury Correspondence Format Data does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to delete the data with a high impact to availability.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:s\/4hana:104:*:*:*:*:*:*:*
cpe:2.3:a:sap:s\/4hana:105:*:*:*:*:*:*:*

History

21 Nov 2024, 07:48

Type Values Removed Values Added
References () https://launchpad.support.sap.com/#/notes/2985905 - Permissions Required, Vendor Advisory () https://launchpad.support.sap.com/#/notes/2985905 - Permissions Required, Vendor Advisory
References () https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory () https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory

Information

Published : 2023-02-14 04:15

Updated : 2024-11-21 07:48


NVD link : CVE-2023-24524

Mitre link : CVE-2023-24524

CVE.ORG link : CVE-2023-24524


JSON object : View

Products Affected

sap

  • s\/4hana
CWE
CWE-862

Missing Authorization