CVE Published: 12/03/2024 |
CVE Updated: 02/08/2024 |
CVE Year: 2024 Source: sap |
Vendor: SAP_SE |
Product: SAP ABAP Platform Status : PUBLISHED
CVE-2024-27900 Description
Due to missing authorization check, attacker with business user account in SAP ABAP Platform - version 758, 795, can change the privacy setting of job templates from shared to private. As a result, the selected template would only be accessible to the owner.
Metrics
CVSS Version: 3.1 |
Base Score: 4.3 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N