CVE-2024-34691: Missing Authorization check in SAP S/4HANA (Manage Incoming Payment Files)
Manage Incoming Payment Files (F1680) of SAP S/4HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. As a result, it has high impact on integrity and no impact on the confidentiality and availability of the system.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34691?
CVE-2024-34691 has a high severity due to its potential for privilege escalation.
How do I fix CVE-2024-34691?
Fixing CVE-2024-34691 requires applying the appropriate patches provided by SAP for the affected versions.
Which versions of SAP S/4HANA are affected by CVE-2024-34691?
CVE-2024-34691 affects SAP S/4HANA versions 103, 104, 105, 106, 107, 108, and s4core_102.
What type of impact does CVE-2024-34691 have on the system?
CVE-2024-34691 impacts the integrity of the system by allowing privilege escalation without necessary authorization checks.
Can CVE-2024-34691 affect system confidentiality or availability?
CVE-2024-34691 has no impact on the confidentiality or availability of the system.