CVE Published: 09/07/2024 |
CVE Updated: 02/08/2024 |
CVE Year: 2024 Source: sap |
Vendor: SAP_SE |
Product: SAP CRM WebClient UI Status : PUBLISHED
CVE-2024-37175 Description
SAP CRM WebClient does not
perform necessary authorization check for an authenticated user, resulting in
escalation of privileges. This could allow an attacker to access some sensitive
information.
Metrics
CVSS Version: 3.1 |
Base Score: 4.3 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N