CVE-2024-39592

HIGH

SAP S4CORE - Missing Authorization Leading to Privilege Escalation

Title source: llm
STIX 2.1

Description

Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This allows an attacker to read sensitive information causing high impact on the confidentiality of the application.

References (2)

Core 2
Core References
Permissions Required
https://me.sap.com/notes/3483344

Scores

CVSS v3 7.7
EPSS 0.0036
EPSS Percentile 58.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-862
Status published
Products (7)
sap/s4core 102
sap/s4core 103
sap/s4coreop 104
sap/s4coreop 105
sap/s4coreop 106
sap/s4coreop 107
sap/s4coreop 108
Published Jul 09, 2024
Tracked Since Feb 18, 2026