THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Zendesk (Helpdesk and Chat)

Ok

PUBLISHED

CVE-2024-4139

Missing Authorization Checks in SAP S/4 HANA (Manage Bank Statement Reprocessing Rules)

Reserved:2024-04-24
Published:2024-05-14
Updated:2024-05-14

Description

Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can delete rules of other users affecting the integrity of the application. Confidentiality and Availability are not affected.



MEDIUM: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Problem types

CWE-862: Missing Authorization

Product status

Default status
unaffected

SAPSCORE 131
affected

S4CORE 105
affected

S4CORE 106
affected

S4CORE 107
affected

S4CORE 108
affected

References

https://me.sap.com/notes/3434666

https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html

cve.org CVE-2024-4139

nvd.nist.gov CVE-2024-4139

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-4139