CVE-2024-39592

Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This allows an attacker to read sensitive information causing high impact on the confidentiality of the application.
References
Link Resource
https://me.sap.com/notes/3483344 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory
https://me.sap.com/notes/3483344 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:s4core:102:*:*:*:*:*:*:*
cpe:2.3:a:sap:s4core:103:*:*:*:*:*:*:*
cpe:2.3:a:sap:s4coreop:104:*:*:*:*:*:*:*
cpe:2.3:a:sap:s4coreop:105:*:*:*:*:*:*:*
cpe:2.3:a:sap:s4coreop:106:*:*:*:*:*:*:*
cpe:2.3:a:sap:s4coreop:107:*:*:*:*:*:*:*
cpe:2.3:a:sap:s4coreop:108:*:*:*:*:*:*:*

History

21 Nov 2024, 09:28

Type Values Removed Values Added
References () https://me.sap.com/notes/3483344 - Permissions Required () https://me.sap.com/notes/3483344 - Permissions Required
References () https://url.sap/sapsecuritypatchday - Vendor Advisory () https://url.sap/sapsecuritypatchday - Vendor Advisory
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 7.7

29 Aug 2024, 19:25

Type Values Removed Values Added
First Time Sap s4core
Sap
Sap s4coreop
CPE cpe:2.3:a:sap:s4coreop:104:*:*:*:*:*:*:*
cpe:2.3:a:sap:s4coreop:106:*:*:*:*:*:*:*
cpe:2.3:a:sap:s4coreop:107:*:*:*:*:*:*:*
cpe:2.3:a:sap:s4core:103:*:*:*:*:*:*:*
cpe:2.3:a:sap:s4core:102:*:*:*:*:*:*:*
cpe:2.3:a:sap:s4coreop:108:*:*:*:*:*:*:*
cpe:2.3:a:sap:s4coreop:105:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 7.7
v2 : unknown
v3 : 6.5
References () https://me.sap.com/notes/3483344 - () https://me.sap.com/notes/3483344 - Permissions Required
References () https://url.sap/sapsecuritypatchday - () https://url.sap/sapsecuritypatchday - Vendor Advisory

09 Jul 2024, 18:19

Type Values Removed Values Added
Summary
  • (es) Elements of PDCE no realiza las verificaciones de autorización necesarias para un usuario autenticado, lo que resulta en una escalada de privilegios. Esto permite a un atacante leer información confidencial causando un alto impacto en la confidencialidad de la aplicación.

09 Jul 2024, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 04:15

Updated : 2024-11-21 09:28


NVD link : CVE-2024-39592

Mitre link : CVE-2024-39592

CVE.ORG link : CVE-2024-39592


JSON object : View

Products Affected

sap

  • s4core
  • s4coreop
CWE
CWE-862

Missing Authorization