CVE-2023-24524: Medium severity sap s/4hana vulnerability
SAP S/4 HANA Map Treasury Correspondence Format Data does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to delete the data with a high impact to availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-24524?
CVE-2023-24524 is classified as a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2023-24524?
To address CVE-2023-24524, ensure that proper authorization checks are implemented for the affected SAP S/4 HANA versions.
Which software versions are affected by CVE-2023-24524?
CVE-2023-24524 affects SAP S/4 HANA versions 104 and 105.
What impact does CVE-2023-24524 have?
CVE-2023-24524 can result in a high impact to data availability as it may allow unauthorized deletion of data.
Can CVE-2023-24524 be exploited by authenticated users?
Yes, CVE-2023-24524 can be exploited by an authenticated user due to the lack of necessary authorization checks.