CVE-2024-39596

MEDIUM

SAP Enable Now - Missing Authorization

Title source: llm
STIX 2.1

Description

Due to missing authorization checks, SAP Enable Now allows an author to escalate privileges to access information which should otherwise be restricted. On successful exploitation, the attacker can cause limited impact on confidentiality of the application.

References (2)

Core 2
Core References

Scores

CVSS v3 4.3
EPSS 0.0014
EPSS Percentile 34.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (3)
SAP_SE/SAP Enable Now ENABLE_NOW_CONSUMP_DEL 1704
SAP_SE/SAP Enable Now WPB_MANAGER_CE 10
SAP_SE/SAP Enable Now WPB_MANAGER_HANA 10
Published Jul 09, 2024
Tracked Since Feb 18, 2026