CVE Published: 09/07/2024 |
CVE Updated: 02/08/2024 |
CVE Year: 2024 Source: sap |
Vendor: SAP_SE |
Product: SAP Enable Now Status : PUBLISHED
CVE-2024-39596 Description
Due to missing authorization checks, SAP Enable
Now allows an author to escalate privileges to access information which should
otherwise be restricted. On successful exploitation, the attacker can cause
limited impact on confidentiality of the application.
Metrics
CVSS Version: 3.1 |
Base Score: 4.3 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N