CVE-2024-37172: [CVE-2024-37172] Missing Authorization check in SAP S/4HANA Finance (Advanced Payment Management)
SAP S/4HANA Finance (Advanced Payment Management) does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. As a result, it has a low impact to confidentiality and availability but there is no impact on the integrity.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37172?
CVE-2024-37172 has a low severity rating due to limited impact on confidentiality and availability.
How do I fix CVE-2024-37172?
To resolve CVE-2024-37172, apply the latest security updates and patches provided by SAP for the affected versions.
What impact does CVE-2024-37172 have on my system?
CVE-2024-37172 allows for privilege escalation without compromising integrity, affecting system confidentiality and availability.
Which versions of SAP S/4HANA are affected by CVE-2024-37172?
CVE-2024-37172 affects SAP S/4HANA Finance versions 107 and 108, among others.
Is there a workaround for CVE-2024-37172?
Currently, the best recommendation for CVE-2024-37172 is to apply the necessary security updates from SAP rather than relying on a workaround.