CVE-2024-45282

MEDIUM

Fields in 'Read Only' State - Info Disclosure

Title source: llm
STIX 2.1

Description

Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be modified by MERGE method. The property of an OData entity representing assumably immutable method is not protected against external modifications leading to integrity violations. Confidentiality and Availability are not impacted.

References (2)

Core 2
Core References
Permissions Required
https://me.sap.com/notes/3251893

Scores

CVSS v3 4.3
EPSS 0.0027
EPSS Percentile 50.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-650
Status published
Products (6)
sap/s\/4_hana 102
sap/s\/4_hana 103
sap/s\/4_hana 104
sap/s\/4_hana 105
sap/s\/4_hana 106
sap/s\/4_hana 107
Published Oct 08, 2024
Tracked Since Feb 18, 2026