Vulnerability Description
Manage Incoming Payment Files (F1680) of SAP S/4HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. As a result, it has high impact on integrity and no impact on the confidentiality and availability of the system.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | S\/4 Hana | 103 |
Related Weaknesses (CWE)
References
- https://me.sap.com/notes/3466175Permissions Required
- https://support.sap.com/en/my-support/knowledge-base/security-notes-news.htmlPatchVendor Advisory
- https://me.sap.com/notes/3466175Permissions Required
- https://support.sap.com/en/my-support/knowledge-base/security-notes-news.htmlPatchVendor Advisory
FAQ
What is CVE-2024-34691?
CVE-2024-34691 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Manage Incoming Payment Files (F1680) of SAP S/4HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. As a result, it has high impact o...
How severe is CVE-2024-34691?
CVE-2024-34691 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-34691?
Check the references section above for vendor advisories and patch information. Affected products include: Sap S\/4 Hana.