PT-2024-31538 · Sap · Sap Gui

Published

2024-09-09

·

Updated

2024-09-10

·

CVE-2024-45285

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions SAP GUI (affected versions not specified)
Description The issue allows a low-privileged user to perform a denial of service on any user and also change or delete favourite nodes. This is achieved by sending a crafted packet in the function module targeting specific parameters, resulting in the targeted user losing access to SAP GUI functionality. The impact on the application's integrity and availability is low.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-45285

Affected Products

Sap Gui