SAP My Travel Requests does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker can upload a malicious attachment to a business trip request which will lead to a low impact on the confidentiality, integrity and availability of the application.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: sap
Published: 2024-05-14T03:07:12.283Z
Updated: 2024-08-02T02:20:35.313Z
Reserved: 2024-04-17T10:46:51.752Z
Link: CVE-2024-32731
Vulnrichment
Updated: 2024-08-02T02:20:35.313Z
NVD
Status : Awaiting Analysis
Published: 2024-05-14T16:17:08.977
Modified: 2024-05-14T19:17:55.627
Link: CVE-2024-32731
Redhat
No data.