CVE-2024-22133
Improper Access Control in SAP Fiori Front End Server
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
SAP Fiori Front End Server - version 605, allows altering of approver details on the read-only field when sending leave request information. This could lead to creation of request with incorrect approver causing low impact on Confidentiality and Integrity with no impact on Availability of the application.
SAP Fiori Front End Server: versión 605, permite modificar los detalles del aprobador en el campo de solo lectura al enviar información de solicitud de licencia. Esto podría dar lugar a la creación de una solicitud con un aprobador incorrecto, lo que provocaría un bajo impacto en la confidencialidad y la integridad, sin ningún impacto en la disponibilidad de la aplicación.
SAP Fiori Front End Server - version 605, allows altering of approver details on the read-only field when sending leave request information. This could lead to creation of request with incorrect approver causing low impact on Confidentiality and Integrity with no impact on Availability of the application.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-01-05 CVE Reserved
- 2024-03-12 CVE Published
- 2024-03-12 EPSS Updated
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-863: Incorrect Authorization
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://me.sap.com/notes/3417399 | ||
https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
SAP SE Search vendor "SAP SE" | SAP Fiori Front End Server Search vendor "SAP SE" for product "SAP Fiori Front End Server" | 605 Search vendor "SAP SE" for product "SAP Fiori Front End Server" and version "605" | en |
Affected
|