SAP Group Reporting Data Collection does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, specific data can be changed via the Enter Package Data app although the user does not have sufficient authorization causing high impact on Integrity of the appliction.
References
Configurations
No configuration.
History
21 Nov 2024, 09:05
Type | Values Removed | Values Added |
---|---|---|
References | () https://me.sap.com/notes/3442378 - | |
References | () https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364 - |
09 Apr 2024, 12:48
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
09 Apr 2024, 01:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-09 01:15
Updated : 2024-11-21 09:05
NVD link : CVE-2024-28167
Mitre link : CVE-2024-28167
CVE.ORG link : CVE-2024-28167
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization