Due to missing authorization check in SAP for Oil & Gas (Transportation and Distribution), an attacker authenticated as a non-administrative user could call a remote-enabled function which will allow them to delete non-sensitive entries in a user data table. There is no effect on confidentiality or availability.
Metrics
Affected Vendors & Products
References
History
Mon, 16 Sep 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap oil \%\/ Gas |
|
| CPEs | cpe:2.3:a:sap:oil_\%\/_gas:600:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:602:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:603:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:604:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:605:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:606:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:617:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:618:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:800:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:802:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:803:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:804:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:805:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:806:*:*:*:*:*:*:* cpe:2.3:a:sap:oil_\%\/_gas:807:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sap
Sap oil \%\/ Gas |
Tue, 10 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Sep 2024 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to missing authorization check in SAP for Oil & Gas (Transportation and Distribution), an attacker authenticated as a non-administrative user could call a remote-enabled function which will allow them to delete non-sensitive entries in a user data table. There is no effect on confidentiality or availability. | |
| Title | Missing Authorization check in SAP for Oil & Gas (Transportation and Distribution) | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2024-09-10T04:03:08.115Z
Updated: 2024-09-10T13:24:25.562Z
Reserved: 2024-08-20T20:22:59.936Z
Link: CVE-2024-44112
Updated: 2024-09-10T13:24:21.948Z
Status : Analyzed
Published: 2024-09-10T04:15:04.710
Modified: 2024-09-16T14:19:24.917
Link: CVE-2024-44112
No data.