CVE-2023-24528: Medium severity sap fiori vulnerability

Published Feb 14, 2023
·
Updated

SAP Fiori apps for Travel Management in SAP ERP (My Travel Requests) - version 600, allows an authenticated attacker to exploit a certain misconfigured application endpoint to view sensitive data. This endpoint is normally exposed over the network and successful exploitation can lead to exposure of data like travel documents.

Affected Software

1 affected component
SAP Fiori=600

Event History

Feb 14, 2023
CVE Published
via MITRE·03:18 AM
Data Sourced
via MITRE·03:18 AM
DescriptionSeverity

Frequently Asked Questions

1

What is the severity of CVE-2023-24528?

The severity of CVE-2023-24528 is considered high due to the potential risk of sensitive data exposure.

2

How can I fix CVE-2023-24528?

To fix CVE-2023-24528, review and secure the misconfigured application endpoint in the SAP Fiori apps for Travel Management.

3

Who is affected by CVE-2023-24528?

CVE-2023-24528 affects users of SAP Fiori version 600 specifically related to Travel Management applications.

4

What are the implications of CVE-2023-24528?

The implications of CVE-2023-24528 include unauthorized access to sensitive user data through the exposed application endpoint.

5

Is authentication required to exploit CVE-2023-24528?

Yes, exploiting CVE-2023-24528 requires authenticated access to the SAP Fiori applications.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203