PT-2024-6127 · Sap · Sap Shared Service Framework

Published

2024-08-12

·

Updated

2025-12-17

·

CVE-2024-42376

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP Shared Service Framework (affected versions not specified)
Description The issue is related to the SAP Shared Service Framework, which does not perform necessary authorization checks for authenticated users. This results in an escalation of privileges. On successful exploitation, an attacker can cause a high impact on the confidentiality of the application. The vulnerability can be exploited by a remote attacker to gain unauthorized access to protected information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-07043
CVE-2024-42376

Affected Products

Sap Shared Service Framework