7.3
CVE-2024-21735
- EPSS 0.15%
- Veröffentlicht 09.01.2024 01:15:39
- Zuletzt bearbeitet 21.11.2024 08:54:54
- Quelle cna@sap.com
- Teams Watchlist Login
- Unerledigt Login
SAP LT Replication Server - version S4CORE 103, S4CORE 104, S4CORE 105, S4CORE 106, S4CORE 107, S4CORE 108, does not perform necessary authorization checks. This could allow an attacker with high privileges to perform unintended actions, resulting in escalation of privileges, which has High impact on confidentiality, integrity and availability of the system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Lt Replication Server Versions4core_103
SAP ≫ Lt Replication Server Versions4core_104
SAP ≫ Lt Replication Server Versions4core_105
SAP ≫ Lt Replication Server Versions4core_106
SAP ≫ Lt Replication Server Versions4core_107
SAP ≫ Lt Replication Server Versions4core_108
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.15% | 0.357 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
cna@sap.com | 7.3 | 0.7 | 6 |
CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.