5.3

CVE-2024-45282

HTTP Verb Tampering in SAP S/4 HANA(Manage Bank Statements)

Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be modified by MERGE method. The property of an OData entity representing assumably immutable method is not protected against external modifications leading to integrity violations. Confidentiality and Availability are not impacted.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ S/4 Hana Version 102
SAP ≫ S/4 Hana Version 103
SAP ≫ S/4 Hana Version 104
SAP ≫ S/4 Hana Version 105
SAP ≫ S/4 Hana Version 106
SAP ≫ S/4 Hana Version 107
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.22
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
SAP 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CWE-650 Trusting HTTP Permission Methods on the Server Side

The server contains a protection mechanism that assumes that any URI that is accessed using HTTP GET will not cause a state change to the associated resource. This might allow attackers to bypass intended access restrictions and conduct resource modification and deletion attacks, since some applications allow GET to modify state.

https://url.sap/sapsecuritypatchday
Vendor Advisory
https://me.sap.com/notes/3251893
Permissions Required