6.5

CVE-2024-39592

Medienbericht

[CVE-2024-39592] Missing Authorization check in SAP PDCE

Elements of PDCE does not perform necessary
authorization checks for an authenticated user, resulting in escalation of
privileges.



This
allows an attacker to read sensitive information causing high impact on the
confidentiality of the application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ S4core Version 102
SAP ≫ S4core Version 103
SAP ≫ S4coreop Version 104
SAP ≫ S4coreop Version 105
SAP ≫ S4coreop Version 106
SAP ≫ S4coreop Version 107
SAP ≫ S4coreop Version 108
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.42% 0.334
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
SAP 7.7 3.1 4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
09.08.2025 11:36
https://url.sap/sapsecuritypatchday
Vendor Advisory
https://me.sap.com/notes/3483344
Permissions Required