CVE-2024-44121

MEDIUM

SAP S/4 HANA (Statutory Reports) - Exposure of Sensitive Internal User Data

Title source: llm
STIX 2.1

Description

Under certain conditions Statutory Reports in SAP S/4 HANA allows an attacker with basic privileges to access information which would otherwise be restricted. The vulnerability could expose internal user data that should remain confidential. It does not impact the integrity and availability of the application

References (2)

Core 2
Core References

Scores

CVSS v3 4.3
EPSS 0.0014
EPSS Percentile 34.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-213
Status published
Products (1)
SAP_SE/SAP S/4 HANA (Statutory Reports) 900
Published Sep 10, 2024
Tracked Since Feb 18, 2026