CVE-2024-39593

SAP Landscape Management allows an authenticated user to read confidential data disclosed by the REST Provider Definition response. Successful exploitation can cause high impact on confidentiality of the managed entities.
References
Link Resource
https://me.sap.com/notes/3466801 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory
https://me.sap.com/notes/3466801 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:sap:landscape_management:3.0:*:*:*:*:*:*:*

History

21 Nov 2024, 09:28

Type Values Removed Values Added
References () https://me.sap.com/notes/3466801 - Permissions Required () https://me.sap.com/notes/3466801 - Permissions Required
References () https://url.sap/sapsecuritypatchday - Vendor Advisory () https://url.sap/sapsecuritypatchday - Vendor Advisory
CVSS v2 : unknown
v3 : 5.7
v2 : unknown
v3 : 6.9

29 Aug 2024, 19:08

Type Values Removed Values Added
References () https://me.sap.com/notes/3466801 - () https://me.sap.com/notes/3466801 - Permissions Required
References () https://url.sap/sapsecuritypatchday - () https://url.sap/sapsecuritypatchday - Vendor Advisory
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : 6.9
v2 : unknown
v3 : 5.7
First Time Sap landscape Management
Sap
CPE cpe:2.3:a:sap:landscape_management:3.0:*:*:*:*:*:*:*

09 Jul 2024, 18:19

Type Values Removed Values Added
Summary
  • (es) SAP Landscape Management permite a un usuario autenticado leer datos confidenciales revelados por la respuesta de Provider Definition REST. La explotación exitosa puede causar un gran impacto en la confidencialidad de las entidades gestionadas.

09 Jul 2024, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 04:15

Updated : 2024-11-21 09:28


NVD link : CVE-2024-39593

Mitre link : CVE-2024-39593

CVE.ORG link : CVE-2024-39593


JSON object : View

Products Affected

sap

  • landscape_management
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo