CVE-2024-39591

MEDIUM

SAP Document Builder - Missing Authorization

Title source: llm
STIX 2.1

Description

SAP Document Builder does not perform necessary authorization checks for one of the function modules resulting in escalation of privileges causing low impact on confidentiality of the application.

References (2)

Core 2
Core References
Permissions Required
https://me.sap.com/notes/3477423

Scores

CVSS v3 4.3
EPSS 0.0041
EPSS Percentile 61.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (12)
sap/document_builder s4fnd_102
sap/document_builder s4fnd_103
sap/document_builder s4fnd_104
sap/document_builder s4fnd_105
sap/document_builder s4fnd_106
sap/document_builder s4fnd_107
sap/document_builder s4fnd_108
sap/document_builder sap_bs_fnd_702
sap/document_builder sap_bs_fnd_731
sap/document_builder sap_bs_fnd_746
... and 2 more
Published Aug 13, 2024
Tracked Since Feb 18, 2026