CVE-2024-39592
[CVE-2024-39592] Missing Authorization check in SAP PDCE
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Elements of PDCE does not perform necessary
authorization checks for an authenticated user, resulting in escalation of
privileges. This
allows an attacker to read sensitive information causing high impact on the
confidentiality of the application.
Elements of PDCE no realiza las verificaciones de autorización necesarias para un usuario autenticado, lo que resulta en una escalada de privilegios. Esto permite a un atacante leer información confidencial causando un alto impacto en la confidencialidad de la aplicación.
Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This allows an attacker to read sensitive information causing high impact on the confidentiality of the application.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-06-26 CVE Reserved
- 2024-07-09 CVE Published
- 2024-08-02 CVE Updated
- 2024-08-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-862: Missing Authorization
CAPEC
References (2)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sap Search vendor "Sap" | S4core Search vendor "Sap" for product "S4core" | * | - |
Affected
| ||||||
Sap Search vendor "Sap" | S4coreop Search vendor "Sap" for product "S4coreop" | * | - |
Affected
| ||||||
Sap Se Search vendor "Sap Se" | Sap Pdce Search vendor "Sap Se" for product "Sap Pdce" | * | - |
Affected
|