First published: Tue Mar 12 2024(Updated: )
Due to missing authorization check, attacker with business user account in SAP ABAP Platform - version 758, 795, can change the privacy setting of job templates from shared to private. As a result, the selected template would only be accessible to the owner.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP ABAP | >=758<=795 | |
SAP ABAP | =758 | |
SAP ABAP | =795 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-27900 has a medium severity due to the potential access controls being improperly managed.
To fix CVE-2024-27900, apply the latest security patch released by SAP for the affected versions of the ABAP Platform.
CVE-2024-27900 affects SAP ABAP Platform versions from 758 to 795.
CVE-2024-27900 allows an attacker with a business user account to change the privacy settings of job templates, limiting access to the owner.
Users with business accounts on the affected versions of SAP ABAP Platform are at risk from CVE-2024-27900.