CVE-2024-37175

SAP CRM WebClient does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to access some sensitive information.
References
Link Resource
https://me.sap.com/notes/3467377 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory
https://me.sap.com/notes/3467377 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:customer_relationship_management_s4fnd:102:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_s4fnd:103:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_s4fnd:104:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_s4fnd:105:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_s4fnd:106:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_s4fnd:107:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_s4fnd:108:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:701:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:731:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:746:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:747:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:748:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:800:*:*:*:*:*:*:*
cpe:2.3:a:sap:customer_relationship_management_webclient_ui:801:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-07-09 05:15

Updated : 2024-11-21 09:23


NVD link : CVE-2024-37175

Mitre link : CVE-2024-37175

CVE.ORG link : CVE-2024-37175


JSON object : View

Products Affected

sap

  • customer_relationship_management_s4fnd
  • customer_relationship_management_webclient_ui
CWE
CWE-862

Missing Authorization