PT-2024-23261 · Sap · Sap S/4Hana

Published

2024-04-08

·

Updated

2024-04-09

·

CVE-2024-30216

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP S/4 HANA (affected versions not specified)
Description The issue is related to the Cash Management component in SAP S/4 HANA, where it fails to perform necessary authorization checks for an authenticated user. This results in an escalation of privileges. An attacker can exploit this to add notes in the review request with a 'completed' status, affecting the integrity of the application. Confidentiality and Availability are not impacted.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-30216

Affected Products

Sap S/4Hana