PT-2024-3900 · Sap · Sap Bank Account Management

Published

2024-02-12

·

Updated

2024-10-16

·

CVE-2024-24739

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: SAP Bank Account Management (BAM) (affected versions not specified)
Description: The issue is related to the lack of an authorization procedure in SAP Bank Account Management (BAM), which can allow a remote attacker to escalate their privileges. This can result in an authenticated user with restricted access using certain functions, leading to an escalation of privileges with a low impact on the confidentiality, integrity, and availability of the application.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-04307
CVE-2024-24739

Affected Products

Sap Bank Account Management