Due to missing authorization check in SAP for Oil & Gas (Transportation and Distribution), an attacker authenticated as a non-administrative user could call a remote-enabled function which will allow them to delete non-sensitive entries in a user data table. There is no effect on confidentiality or availability.
References
Link | Resource |
---|---|
https://me.sap.com/notes/3505293 | Permissions Required |
https://url.sap/sapsecuritypatchday | Patch |
Configurations
Configuration 1 (hide)
|
History
16 Sep 2024, 14:19
Type | Values Removed | Values Added |
---|---|---|
First Time |
Sap
Sap oil \%\/ Gas |
|
References | () https://me.sap.com/notes/3505293 - Permissions Required | |
References | () https://url.sap/sapsecuritypatchday - Patch | |
CPE | cpe:2.3:a:sap:oil_\%\/_gas:617:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:618:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:605:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:606:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:802:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:604:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:805:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:602:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:803:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:804:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:600:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:806:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:807:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:800:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:603:*:*:*:*:*:*:* |
10 Sep 2024, 12:09
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
10 Sep 2024, 04:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-10 04:15
Updated : 2024-09-16 14:19
NVD link : CVE-2024-44112
Mitre link : CVE-2024-44112
CVE.ORG link : CVE-2024-44112
JSON object : View
Products Affected
sap
- oil_\%\/_gas
CWE
CWE-862
Missing Authorization