CVE-2024-44112

Due to missing authorization check in SAP for Oil & Gas (Transportation and Distribution), an attacker authenticated as a non-administrative user could call a remote-enabled function which will allow them to delete non-sensitive entries in a user data table. There is no effect on confidentiality or availability.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:oil_\%\/_gas:600:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:602:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:603:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:604:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:605:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:606:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:617:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:618:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:800:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:802:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:803:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:804:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:805:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:806:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:807:*:*:*:*:*:*:*

History

16 Sep 2024, 14:19

Type Values Removed Values Added
First Time Sap
Sap oil \%\/ Gas
References () https://me.sap.com/notes/3505293 - () https://me.sap.com/notes/3505293 - Permissions Required
References () https://url.sap/sapsecuritypatchday - () https://url.sap/sapsecuritypatchday - Patch
CPE cpe:2.3:a:sap:oil_\%\/_gas:617:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:618:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:605:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:606:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:802:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:604:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:805:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:602:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:803:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:804:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:600:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:806:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:807:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:800:*:*:*:*:*:*:*
cpe:2.3:a:sap:oil_\%\/_gas:603:*:*:*:*:*:*:*

10 Sep 2024, 12:09

Type Values Removed Values Added
Summary
  • (es) Debido a la falta de verificación de autorización en SAP para petróleo y gas (transporte y distribución), un atacante autenticado como usuario no administrativo podría llamar a una función habilitada de forma remota que le permita eliminar entradas no confidenciales en una tabla de datos de usuario. No hay ningún efecto sobre la confidencialidad o la disponibilidad.

10 Sep 2024, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-10 04:15

Updated : 2024-09-16 14:19


NVD link : CVE-2024-44112

Mitre link : CVE-2024-44112

CVE.ORG link : CVE-2024-44112


JSON object : View

Products Affected

sap

  • oil_\%\/_gas
CWE
CWE-862

Missing Authorization