First published: Tue Jul 09 2024(Updated: )
SAP Landscape Management allows an authenticated user to read confidential data disclosed by the REST Provider Definition response. Successful exploitation can cause high impact on confidentiality of the managed entities.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Landscape Management | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-39593 has a high severity rating due to its potential impact on the confidentiality of sensitive data.
To fix CVE-2024-39593, ensure that you apply the latest security patches provided by SAP for Landscape Management.
CVE-2024-39593 affects confidential data that can be disclosed through the REST Provider Definition response.
Authenticated users of SAP Landscape Management 3.0 are affected by CVE-2024-39593.
An attacker exploiting CVE-2024-39593 can gain unauthorized access to confidential data, significantly impacting the confidentiality of managed entities.