S
AP BW/4HANA Transformation and Data Transfer Process (DTP) allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization checks. This results in escalation of privileges. It has no impact on the confidentiality of data but may have low impacts on the integrity and availability of the application.
References
| Link | Resource |
|---|---|
| https://me.sap.com/notes/3465455 | Permissions Required |
| https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html | Patch Vendor Advisory |
| https://me.sap.com/notes/3465455 | Permissions Required |
| https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 09:23
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
| References | () https://me.sap.com/notes/3465455 - Permissions Required | |
| References | () https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html - Patch, Vendor Advisory |
09 Aug 2024, 18:42
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:sap:bw\/4hana:dw4core_200:*:*:*:*:*:*:* cpe:2.3:a:sap:bw\/4hana:756:*:*:*:*:*:*:* cpe:2.3:a:sap:bw\/4hana:755:*:*:*:*:*:*:* cpe:2.3:a:sap:bw\/4hana:400:*:*:*:*:*:*:* cpe:2.3:a:sap:bw\/4hana:sap_bw_740:*:*:*:*:*:*:* cpe:2.3:a:sap:bw\/4hana:796:*:*:*:*:*:*:* cpe:2.3:a:sap:bw\/4hana:751:*:*:*:*:*:*:* cpe:2.3:a:sap:bw\/4hana:300:*:*:*:*:*:*:* cpe:2.3:a:sap:bw\/4hana:757:*:*:*:*:*:*:* cpe:2.3:a:sap:bw\/4hana:750:*:*:*:*:*:*:* cpe:2.3:a:sap:bw\/4hana:758:*:*:*:*:*:*:* cpe:2.3:a:sap:bw\/4hana:753:*:*:*:*:*:*:* cpe:2.3:a:sap:bw\/4hana:754:*:*:*:*:*:*:* cpe:2.3:a:sap:bw\/4hana:752:*:*:*:*:*:*:* |
|
| References | () https://me.sap.com/notes/3465455 - Permissions Required | |
| References | () https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html - Patch, Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
| First Time |
Sap
Sap bw\/4hana |
11 Jun 2024, 13:54
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-06-11 03:15
Updated : 2024-11-21 09:23
NVD link : CVE-2024-37176
Mitre link : CVE-2024-37176
CVE.ORG link : CVE-2024-37176
JSON object : View
CWE
CWE-862
Missing Authorization