CVE-2024-25642
HIGHSAP Cloud Connector 2.0 - Improper Certificate Validation
Title source: llmDescription
Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the genuine servers to interact with SCC breaking the mutual authentication. Hence, the attacker can intercept the request to view/modify sensitive information. There is no impact on the availability of the system.
References (3)
Core 3
Core References
Mailing List, Third Party Advisory
http://seclists.org/fulldisclosure/2024/May/26
Permissions Required
https://me.sap.com/notes/3424610
Scores
CVSS v3
7.4
EPSS
0.0043
EPSS Percentile
63.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-295
Status
published
Products (1)
sap/cloud_connector
2.0
Published
Feb 13, 2024
Tracked Since
Feb 18, 2026