First published: Tue Jan 09 2024(Updated: )
SAP S/4HANA Finance for (Advanced Payment Management) - versions SAPSCORE 128, S4CORE 107, does not perform necessary authorization checks. A function import could be triggered allowing the attacker to create in-house bank accounts leading to low impact on the confidentiality of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP S/4HANA Finance | =107 | |
SAP S/4HANA Finance | =128 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21736 has a low impact on confidentiality due to its authorization check vulnerability.
To fix CVE-2024-21736, ensure that proper authorization checks are implemented for function imports in affected versions of SAP S/4HANA Finance.
CVE-2024-21736 affects SAP S/4HANA Finance versions 107 and 128.
CVE-2024-21736 is an authorization check vulnerability allowing unauthorized creation of in-house bank accounts.
While CVE-2024-21736 has low impact on confidentiality, exploitation could lead to unauthorized access to banking functionalities.