CVE-2023-24528: Medium severity sap fiori vulnerability
SAP Fiori apps for Travel Management in SAP ERP (My Travel Requests) - version 600, allows an authenticated attacker to exploit a certain misconfigured application endpoint to view sensitive data. This endpoint is normally exposed over the network and successful exploitation can lead to exposure of data like travel documents.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-24528?
The severity of CVE-2023-24528 is considered high due to the potential risk of sensitive data exposure.
How can I fix CVE-2023-24528?
To fix CVE-2023-24528, review and secure the misconfigured application endpoint in the SAP Fiori apps for Travel Management.
Who is affected by CVE-2023-24528?
CVE-2023-24528 affects users of SAP Fiori version 600 specifically related to Travel Management applications.
What are the implications of CVE-2023-24528?
The implications of CVE-2023-24528 include unauthorized access to sensitive user data through the exposed application endpoint.
Is authentication required to exploit CVE-2023-24528?
Yes, exploiting CVE-2023-24528 requires authenticated access to the SAP Fiori applications.