Due to missing authorization check in SAP for Oil & Gas (Transportation and Distribution), an attacker authenticated as a non-administrative user could call a remote-enabled function which will allow them to delete non-sensitive entries in a user data table. There is no effect on confidentiality or availability.
Metrics
Affected Vendors & Products
References
History
Mon, 16 Sep 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sap
Sap oil \%\/ Gas |
|
CPEs | cpe:2.3:a:sap:oil_\%\/_gas:600:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:602:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:603:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:604:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:605:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:606:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:617:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:618:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:800:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:802:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:803:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:804:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:805:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:806:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:807:*:*:*:*:*:*:* |
|
Vendors & Products |
Sap
Sap oil \%\/ Gas |
Tue, 10 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 10 Sep 2024 04:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Due to missing authorization check in SAP for Oil & Gas (Transportation and Distribution), an attacker authenticated as a non-administrative user could call a remote-enabled function which will allow them to delete non-sensitive entries in a user data table. There is no effect on confidentiality or availability. | |
Title | Missing Authorization check in SAP for Oil & Gas (Transportation and Distribution) | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: sap
Published: 2024-09-10T04:03:08.115Z
Updated: 2024-09-10T13:24:25.562Z
Reserved: 2024-08-20T20:22:59.936Z
Link: CVE-2024-44112
Vulnrichment
Updated: 2024-09-10T13:24:21.948Z
NVD
Status : Analyzed
Published: 2024-09-10T04:15:04.710
Modified: 2024-09-16T14:19:24.917
Link: CVE-2024-44112
Redhat
No data.