Vulnerability Description
Due to missing authorization check in SAP for Oil & Gas (Transportation and Distribution), an attacker authenticated as a non-administrative user could call a remote-enabled function which will allow them to delete non-sensitive entries in a user data table. There is no effect on confidentiality or availability.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Oil \%\/ Gas | 600 |
Related Weaknesses (CWE)
References
- https://me.sap.com/notes/3505293Permissions Required
- https://url.sap/sapsecuritypatchdayPatch
FAQ
What is CVE-2024-44112?
CVE-2024-44112 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Due to missing authorization check in SAP for Oil & Gas (Transportation and Distribution), an attacker authenticated as a non-administrative user could call a remote-enabled function which will allow ...
How severe is CVE-2024-44112?
CVE-2024-44112 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-44112?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Oil \%\/ Gas.