CVE-2024-37175: [Multiple CVEs] Multiple vulnerabilities in SAP CRM (WebClient UI)
SAP CRM WebClient does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to access some sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37175?
CVE-2024-37175 has a high severity due to unauthorized access and privilege escalation risks.
How do I fix CVE-2024-37175?
To fix CVE-2024-37175, apply the latest security patches provided by SAP for the affected versions.
What software is affected by CVE-2024-37175?
CVE-2024-37175 affects several versions of SAP Customer Relationship Management, including versions 102 through 108, and the WebClient UI versions 701 through 801.
What kind of vulnerability is CVE-2024-37175?
CVE-2024-37175 is a privilege escalation vulnerability due to inadequate authorization checks for authenticated users.
Can CVE-2024-37175 allow access to sensitive information?
Yes, CVE-2024-37175 can allow attackers to access sensitive information through unauthorized privilege escalation.