SAP Shared Service Framework does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. On successful exploitation, an attacker can cause a high impact on confidentiality of the application.
History

Thu, 12 Sep 2024 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap shared Service Framework
CPEs cpe:2.3:a:sap:shared_service_framework:sap_bs_fnd_702:*:*:*:*:*:*:*
cpe:2.3:a:sap:shared_service_framework:sap_bs_fnd_731:*:*:*:*:*:*:*
cpe:2.3:a:sap:shared_service_framework:sap_bs_fnd_746:*:*:*:*:*:*:*
cpe:2.3:a:sap:shared_service_framework:sap_bs_fnd_747:*:*:*:*:*:*:*
cpe:2.3:a:sap:shared_service_framework:sap_bs_fnd_748:*:*:*:*:*:*:*
Vendors & Products Sap
Sap shared Service Framework

Tue, 13 Aug 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 13 Aug 2024 03:45:00 +0000

Type Values Removed Values Added
Description SAP Shared Service Framework does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. On successful exploitation, an attacker can cause a high impact on confidentiality of the application.
Title Multiple Missing Authorization Check vulnerabilities in SAP Shared Service Framework
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2024-08-13T03:39:04.887Z

Updated: 2024-08-13T18:15:09.197Z

Reserved: 2024-07-31T04:09:36.223Z

Link: CVE-2024-42376

cve-icon Vulnrichment

Updated: 2024-08-13T18:15:06.059Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-13T04:15:10.837

Modified: 2024-09-12T13:43:27.507

Link: CVE-2024-42376

cve-icon Redhat

No data.