Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, attacker can add notes in the review request with 'completed' status affecting the integrity of the application. Confidentiality and Availability are not impacted.
References
Configurations
No configuration.
History
21 Nov 2024, 09:11
Type | Values Removed | Values Added |
---|---|---|
References | () https://me.sap.com/notes/3427178 - | |
References | () https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364 - |
09 Apr 2024, 12:48
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
09 Apr 2024, 01:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-09 01:15
Updated : 2024-11-21 09:11
NVD link : CVE-2024-30216
Mitre link : CVE-2024-30216
CVE.ORG link : CVE-2024-30216
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization