ZeroHour

CVE-2024-37175

CVSS 3.1
6.5 medium
EPSS
<1%p23
Published
()
Modified
Description

SAP CRM WebClient does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to access some sensitive information.

Vendors
sap
Products
customer relationship management s4fnd, customer relationship management webclient ui
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.