CVE-2024-37175

MEDIUM

SAP CRM WebClient UI - Missing Authorization Check

Title source: llm
STIX 2.1

Description

SAP CRM WebClient does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to access some sensitive information.

References (2)

Core 2
Core References
Permissions Required
https://me.sap.com/notes/3467377

Scores

CVSS v3 4.3
EPSS 0.0030
EPSS Percentile 53.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (14)
sap/customer_relationship_management_s4fnd 102
sap/customer_relationship_management_s4fnd 103
sap/customer_relationship_management_s4fnd 104
sap/customer_relationship_management_s4fnd 105
sap/customer_relationship_management_s4fnd 106
sap/customer_relationship_management_s4fnd 107
sap/customer_relationship_management_s4fnd 108
sap/customer_relationship_management_webclient_ui 701
sap/customer_relationship_management_webclient_ui 731
sap/customer_relationship_management_webclient_ui 746
... and 4 more
Published Jul 09, 2024
Tracked Since Feb 18, 2026