PT-2024-1561 · Sap · Sap Lt Replication Server

Published

2024-01-08

·

Updated

2024-01-30

·

CVE-2024-21735

CVSS v3.1

7.3

High

VectorAV:A/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP LT Replication Server versions S4CORE 103 through S4CORE 108
Description The issue is related to improper authorization in the SAP LT Replication Server. This could allow a remote attacker with high privileges to perform unintended actions, resulting in escalation of privileges. The impact of this issue is high on the confidentiality, integrity, and availability of the system.
Recommendations For versions S4CORE 103 through S4CORE 108, apply the necessary patches or updates to ensure proper authorization checks are performed. As a temporary workaround, consider restricting access to the system to minimize the risk of exploitation. Ensure that all users with high privileges are carefully monitored and that their actions are regularly audited to detect any potential security breaches.

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-01106
CVE-2024-21735

Affected Products

Sap Lt Replication Server