We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Zendesk (Helpdesk and Chat)
Ok

THREATINT
PUBLISHED

CVE-2024-4138

Missing Authorization Checks in SAP S/4 HANA (Manage Bank Statement Reprocessing Rules)

Reserved:2024-04-24
Published:2024-05-14
Updated:2024-05-14

Description

Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can enable/disable the sharing rule of other users affecting the integrity of the application. Confidentiality and Availability are not affected.



MEDIUM: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Problem types

CWE-862: Missing Authorization

Product status

Default status
unaffected

SAPSCORE 131
affected

S4CORE 105
affected

S4CORE 106
affected

S4CORE107
affected

S4CORE 108
affected

References

https://me.sap.com/notes/3434666

https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html

cve.org CVE-2024-4138

nvd.nist.gov CVE-2024-4138

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-4138