ZeroHour

CVE-2024-42376

CVSS 3.1
6.5 medium
EPSS
<1%p25
Published
()
Modified
Description

SAP Shared Service Framework does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. On successful exploitation, an attacker can cause a high impact on confidentiality of the application.

Vendors
sap
Products
shared service framework
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.