5.4

CVE-2024-37176

Missing Authorization check in SAP BW/4HANA Transformation and DTP

SAP BW/4HANA Transformation and Data Transfer
Process (DTP) allows an authenticated attacker to gain higher access levels
than they should have by exploiting improper authorization checks. This results
in escalation of privileges. It has no impact on the confidentiality of data
but may have low impacts on the integrity and availability of the application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Bw/4hana Version 300
SAP ≫ Bw/4hana Version 400
SAP ≫ Bw/4hana Version 750
SAP ≫ Bw/4hana Version 751
SAP ≫ Bw/4hana Version 752
SAP ≫ Bw/4hana Version 753
SAP ≫ Bw/4hana Version 754
SAP ≫ Bw/4hana Version 755
SAP ≫ Bw/4hana Version 756
SAP ≫ Bw/4hana Version 757
SAP ≫ Bw/4hana Version 758
SAP ≫ Bw/4hana Version 796
SAP ≫ Bw/4hana Version dw4core_200
SAP ≫ Bw/4hana Version sap_bw_740
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.28% 0.192
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
SAP 5.5 2.3 2.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html
Patch
Vendor Advisory
https://me.sap.com/notes/3465455
Permissions Required