Due to missing authorization checks, SAP Business Warehouse (BEx Analyzer) allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker can enumerate information causing a limited impact on confidentiality of the application.
History

Tue, 10 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Sep 2024 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862

Tue, 10 Sep 2024 03:15:00 +0000

Type Values Removed Values Added
Description Due to missing authorization checks, SAP Business Warehouse (BEx Analyzer) allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker can enumerate information causing a limited impact on confidentiality of the application.
Title Information Disclosure vulnerability in the SAP Business Warehouse (BEx Analyzer)
Weaknesses CWE-359
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2024-09-10T03:04:28.683Z

Updated: 2024-09-10T13:27:59.898Z

Reserved: 2024-08-20T20:22:59.936Z

Link: CVE-2024-44113

cve-icon Vulnrichment

Updated: 2024-09-10T13:27:40.889Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-10T03:15:02.860

Modified: 2024-09-10T12:09:50.377

Link: CVE-2024-44113

cve-icon Redhat

No data.