PT-2024-19219 · Sap · Sap Fiori Front End Server

Published

2024-03-11

·

Updated

2024-03-16

·

CVE-2024-22133

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP Fiori Front End Server version 605
Description The issue allows altering of approver details on the read-only field when sending leave request information, potentially leading to the creation of requests with incorrect approvers. This could cause low impact on Confidentiality and Integrity with no impact on Availability of the application.
Recommendations For SAP Fiori Front End Server version 605, consider restricting access to the leave request functionality until a patch is available to prevent alteration of approver details. As a temporary workaround, disabling the ability to edit approver details in the read-only field may help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-22133

Affected Products

Sap Fiori Front End Server