Unauthorized Access to Sensitive Data via Tobin Interface
CVE-2024-45286
6.5MEDIUM
Key Information
- Vendor
- SAP
- Status
- SAP Production And Revenue Accounting (tobin Interface)
- Vendor
- CVE Published:
- 10 September 2024
Summary
Due to lack of proper authorization checks when calling user, a function module in obsolete Tobin interface in SAP Production and Revenue Accounting allows unauthorized access that could lead to disclosure of highly sensitive data. There is no impact on integrity or availability.
Affected Version(s)
SAP Production and Revenue Accounting (Tobin interface) = S4CEXT 106
SAP Production and Revenue Accounting (Tobin interface) = S4CEXT 107
SAP Production and Revenue Accounting (Tobin interface) = S4CEXT 108
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database