SAP Fiori apps for Travel Management in SAP ERP (My Travel Requests) - version 600, allows an authenticated attacker to exploit a certain misconfigured application endpoint to view sensitive data. This endpoint is normally exposed over the network and successful exploitation can lead to exposure of data like travel documents.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-28546 | SAP Fiori apps for Travel Management in SAP ERP (My Travel Requests) - version 600, allows an authenticated attacker to exploit a certain misconfigured application endpoint to view sensitive data. This endpoint is normally exposed over the network and successful exploitation can lead to exposure of data like travel documents. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 20 Mar 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-03-20T20:22:20.083Z
Reserved: 2023-01-25T15:46:55.581Z
Link: CVE-2023-24528
Updated: 2024-08-02T10:56:04.225Z
Status : Modified
Published: 2023-02-14T04:15:12.870
Modified: 2024-11-21T07:48:03.707
Link: CVE-2023-24528
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD