SAP Group Reporting Data Collection does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, specific data can be changed via the Enter Package Data app although the user does not have sufficient authorization causing high impact on Integrity of the appliction.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2024-25299 | SAP Group Reporting Data Collection does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, specific data can be changed via the Enter Package Data app although the user does not have sufficient authorization causing high impact on Integrity of the appliction. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-08-02T00:48:49.373Z
Reserved: 2024-03-06T06:12:27.005Z
Link: CVE-2024-28167

Updated: 2024-08-01T20:35:32.047Z

Status : Awaiting Analysis
Published: 2024-04-09T01:15:49.380
Modified: 2024-11-21T09:05:56.840
Link: CVE-2024-28167

No data.

No data.