CVE-2024-39596

Due to missing authorization checks, SAP Enable Now allows an author to escalate privileges to access information which should otherwise be restricted. On successful exploitation, the attacker can cause limited impact on confidentiality of the application.
Configurations

No configuration.

History

21 Nov 2024, 09:28

Type Values Removed Values Added
References () https://me.sap.com/notes/3476348 - () https://me.sap.com/notes/3476348 -
References () https://url.sap/sapsecuritypatchday - () https://url.sap/sapsecuritypatchday -

09 Jul 2024, 18:19

Type Values Removed Values Added
Summary
  • (es) Debido a la falta de comprobaciones de autorización, SAP Enable Now permite a un autor escalar privilegios para acceder a información que de otro modo debería estar restringida. Si la explotación tiene éxito, el atacante puede causar un impacto limitado en la confidencialidad de la aplicación.

09 Jul 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 05:15

Updated : 2024-11-21 09:28


NVD link : CVE-2024-39596

Mitre link : CVE-2024-39596

CVE.ORG link : CVE-2024-39596


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization