Unauthorized Access to Sensitive Data via Tobin Interface

CVE-2024-45286
6.5MEDIUM

Key Information

Vendor
SAP
Status
SAP Production And Revenue Accounting (tobin Interface)
Vendor
CVE Published:
10 September 2024

Summary

Due to lack of proper authorization checks when calling user, a function module in obsolete Tobin interface in SAP Production and Revenue Accounting allows unauthorized access that could lead to disclosure of highly sensitive data. There is no impact on integrity or availability.

Affected Version(s)

SAP Production and Revenue Accounting (Tobin interface) = S4CEXT 106

SAP Production and Revenue Accounting (Tobin interface) = S4CEXT 107

SAP Production and Revenue Accounting (Tobin interface) = S4CEXT 108

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.