CVE-2024-27900: Missing Authorization check in SAP ABAP Platform
Due to missing authorization check, attacker with business user account in SAP ABAP Platform - version 758, 795, can change the privacy setting of job templates from shared to private. As a result, the selected template would only be accessible to the owner.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27900?
CVE-2024-27900 has a medium severity due to the potential access controls being improperly managed.
How do I fix CVE-2024-27900?
To fix CVE-2024-27900, apply the latest security patch released by SAP for the affected versions of the ABAP Platform.
What versions of SAP ABAP Platform are affected by CVE-2024-27900?
CVE-2024-27900 affects SAP ABAP Platform versions from 758 to 795.
What impact does CVE-2024-27900 have on SAP ABAP Platform?
CVE-2024-27900 allows an attacker with a business user account to change the privacy settings of job templates, limiting access to the owner.
Who is at risk from CVE-2024-27900?
Users with business accounts on the affected versions of SAP ABAP Platform are at risk from CVE-2024-27900.