← Back

CVE-2024-44112

nvd nist
Published: Sep 10, 2024Modified: Jun 17, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

Due to missing authorization check in SAP for Oil & Gas (Transportation and Distribution), an attacker authenticated as a non-administrative user could call a remote-enabled function which will allow them to delete non-sensitive entries in a user data table. There is no effect on confidentiality or availability.

Affected (15)

Products: Sap: Oil %/ Gas
1 product
Oil %/ Gas
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version 600
Version 602
Version 603
Version 604
Version 605
Version 606
Version 617
Version 618
Version 800
Version 802
Version 803
Version 804
Version 805
Version 806
Version 807

References (2)

Source: cna@sap.com
Permissions Required
Source: cna@sap.com
Patch

Timeline

No history available yet.