CVE Published: 12/11/2024 |
CVE Updated: 12/11/2024 |
CVE Year: 2024 Source: sap |
Vendor: SAP_SE |
Product: SAP NetWeaver AS Java (System Landscape Directory) Status : PUBLISHED
CVE-2024-42372 Description
Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthorized user can read and modify some restricted global SLD configurations causing low impact on confidentiality and integrity of the application.
Metrics
CVSS Version: 3.1 |
Base Score: 6.5 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N