Unauthorized Access to Sensitive Data via Tobin Interface
CVE-2024-45286

6.5MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
10 September 2024

Summary

Due to lack of proper authorization checks when calling user, a function module in obsolete Tobin interface in SAP Production and Revenue Accounting allows unauthorized access that could lead to disclosure of highly sensitive data. There is no impact on integrity or availability.

Affected Version(s)

SAP Production and Revenue Accounting (Tobin interface) S4CEXT 106

SAP Production and Revenue Accounting (Tobin interface) S4CEXT 107

SAP Production and Revenue Accounting (Tobin interface) S4CEXT 108

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.