6.5
CVE-2024-37175
- EPSS 0.3%
- Veröffentlicht 09.07.2024 05:15:11
- Zuletzt bearbeitet 21.11.2024 09:23:21
- Erkennungen
[Multiple CVEs] Multiple vulnerabilities in SAP CRM (WebClient UI)
SAP CRM WebClient does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to access some sensitive information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Customer Relationship Management S4fnd Version 102
SAP ≫ Customer Relationship Management S4fnd Version 103
SAP ≫ Customer Relationship Management S4fnd Version 104
SAP ≫ Customer Relationship Management S4fnd Version 105
SAP ≫ Customer Relationship Management S4fnd Version 106
SAP ≫ Customer Relationship Management S4fnd Version 107
SAP ≫ Customer Relationship Management S4fnd Version 108
SAP ≫ Customer Relationship Management Webclient Ui Version 701
SAP ≫ Customer Relationship Management Webclient Ui Version 731
SAP ≫ Customer Relationship Management Webclient Ui Version 746
SAP ≫ Customer Relationship Management Webclient Ui Version 747
SAP ≫ Customer Relationship Management Webclient Ui Version 748
SAP ≫ Customer Relationship Management Webclient Ui Version 800
SAP ≫ Customer Relationship Management Webclient Ui Version 801
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.218 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| SAP | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
https://url.sap/sapsecuritypatchday
https://me.sap.com/notes/3467377