PT-2024-30958 · Sap · Sap

Published

2024-09-09

·

Updated

2024-09-10

·

CVE-2024-44115

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions SAP (affected versions not specified)
Description The issue allows a low-privileged user to add URLs to any user's workplace favorites through the RFC enabled function module. This could be used to identify usernames and access information about targeted users' workplaces and nodes, with a low impact on the application's integrity.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-44115

Affected Products

Sap