CVE-2024-32730: Missing authorization check in SAP Enable Now Manager
SAP Enable Now Manager does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker with the role 'Learner' could gain access to other user's data in manager which will lead to a high impact to the confidentiality of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32730?
CVE-2024-32730 has a high severity rating due to its potential for privilege escalation.
How do I fix CVE-2024-32730?
To fix CVE-2024-32730, ensure that proper authorization checks are implemented in the SAP Enable Now Manager.
What impact does CVE-2024-32730 have on users?
CVE-2024-32730 allows attackers with the 'Learner' role to access other users' data, compromising user privacy.
Who is affected by CVE-2024-32730?
CVE-2024-32730 affects users of SAP Enable Now Manager who have the 'Learner' role.
Is there a workaround for CVE-2024-32730?
Currently, the recommended approach is to apply an appropriate patch that addresses the lack of authorization checks in SAP Enable Now Manager.