SAP BW/4HANA Transformation and Data Transfer
Process (DTP) allows an authenticated attacker to gain higher access levels
than they should have by exploiting improper authorization checks. This results
in escalation of privileges. It has no impact on the confidentiality of data
but may have low impacts on the integrity and availability of the application.
Process (DTP) allows an authenticated attacker to gain higher access levels
than they should have by exploiting improper authorization checks. This results
in escalation of privileges. It has no impact on the confidentiality of data
but may have low impacts on the integrity and availability of the application.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-36482 | SAP BW/4HANA Transformation and Data Transfer Process (DTP) allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization checks. This results in escalation of privileges. It has no impact on the confidentiality of data but may have low impacts on the integrity and availability of the application. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 09 Aug 2024 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap bw\/4hana |
|
| CPEs | cpe:2.3:a:sap:bw\/4hana:300:*:*:*:*:*:*:* cpe:2.3:a:sap:bw\/4hana:400:*:*:*:*:*:*:* cpe:2.3:a:sap:bw\/4hana:750:*:*:*:*:*:*:* cpe:2.3:a:sap:bw\/4hana:751:*:*:*:*:*:*:* cpe:2.3:a:sap:bw\/4hana:752:*:*:*:*:*:*:* cpe:2.3:a:sap:bw\/4hana:753:*:*:*:*:*:*:* cpe:2.3:a:sap:bw\/4hana:754:*:*:*:*:*:*:* cpe:2.3:a:sap:bw\/4hana:755:*:*:*:*:*:*:* cpe:2.3:a:sap:bw\/4hana:756:*:*:*:*:*:*:* cpe:2.3:a:sap:bw\/4hana:757:*:*:*:*:*:*:* cpe:2.3:a:sap:bw\/4hana:758:*:*:*:*:*:*:* cpe:2.3:a:sap:bw\/4hana:796:*:*:*:*:*:*:* cpe:2.3:a:sap:bw\/4hana:dw4core_200:*:*:*:*:*:*:* cpe:2.3:a:sap:bw\/4hana:sap_bw_740:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sap
Sap bw\/4hana |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-08-02T03:50:54.783Z
Reserved: 2024-06-04T07:49:42.492Z
Link: CVE-2024-37176
Updated: 2024-08-02T03:50:54.783Z
Status : Modified
Published: 2024-06-11T03:15:12.020
Modified: 2024-11-21T09:23:21.937
Link: CVE-2024-37176
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD