We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-39592

[CVE-2024-39592] Missing Authorization check in SAP PDCE



Description

Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This allows an attacker to read sensitive information causing high impact on the confidentiality of the application.

Reserved 2024-06-26 | Published 2024-07-09 | Updated 2024-08-02 | Assigner sap


HIGH: 7.7CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Problem types

CWE-862: Missing Authorization

Product status

Default status
unaffected

S4CORE 102
affected

S4CORE 103
affected

S4COREOP 104
affected

S4COREOP 105
affected

S4COREOP 106
affected

S4COREOP 107
affected

S4COREOP 108
affected

References

url.sap/sapsecuritypatchday

me.sap.com/notes/3483344

cve.org (CVE-2024-39592)

nvd.nist.gov (CVE-2024-39592)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-39592

Support options

Helpdesk Chat, Email, Knowledgebase