Under certain conditions Statutory Reports in SAP S/4 HANA allows an attacker with basic privileges to access information which would otherwise be restricted. The vulnerability could expose internal user data that should remain confidential. It does not impact the integrity and availability of the application
Metrics
Affected Vendors & Products
References
History
Tue, 10 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 10 Sep 2024 04:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Under certain conditions Statutory Reports in SAP S/4 HANA allows an attacker with basic privileges to access information which would otherwise be restricted. The vulnerability could expose internal user data that should remain confidential. It does not impact the integrity and availability of the application | |
Title | Information Disclosure in SAP S/4 HANA (Statutory Reports) | |
Weaknesses | CWE-213 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: sap
Published: 2024-09-10T04:28:07.353Z
Updated: 2024-09-10T13:20:58.919Z
Reserved: 2024-08-20T20:22:59.937Z
Link: CVE-2024-44121
Vulnrichment
Updated: 2024-09-10T13:20:54.866Z
NVD
Status : Awaiting Analysis
Published: 2024-09-10T05:15:11.430
Modified: 2024-09-10T12:09:50.377
Link: CVE-2024-44121
Redhat
No data.