First published: Tue Feb 14 2023(Updated: )
SAP Fiori apps for Travel Management in SAP ERP (My Travel Requests) - version 600, allows an authenticated attacker to exploit a certain misconfigured application endpoint to view sensitive data. This endpoint is normally exposed over the network and successful exploitation can lead to exposure of data like travel documents.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Fiori | =600 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-24528 is considered high due to the potential risk of sensitive data exposure.
To fix CVE-2023-24528, review and secure the misconfigured application endpoint in the SAP Fiori apps for Travel Management.
CVE-2023-24528 affects users of SAP Fiori version 600 specifically related to Travel Management applications.
The implications of CVE-2023-24528 include unauthorized access to sensitive user data through the exposed application endpoint.
Yes, exploiting CVE-2023-24528 requires authenticated access to the SAP Fiori applications.