First published: Tue Oct 08 2024(Updated: )
Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be modified by MERGE method. The property of an OData entity representing assumably immutable method is not protected against external modifications leading to integrity violations. Confidentiality and Availability are not impacted.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap S\/4 Hana | =102 | |
Sap S\/4 Hana | =103 | |
Sap S\/4 Hana | =104 | |
Sap S\/4 Hana | =105 | |
Sap S\/4 Hana | =106 | |
Sap S\/4 Hana | =107 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-45282 is considered a medium severity vulnerability due to its potential to result in data integrity violations.
To mitigate CVE-2024-45282, apply the latest security patches and updates provided by SAP for S/4 HANA versions 102 through 107.
CVE-2024-45282 affects SAP S/4 HANA versions 102, 103, 104, 105, 106, and 107.
CVE-2024-45282 is an integrity vulnerability that allows modification of fields in a read-only state.
Yes, CVE-2024-45282 can potentially be exploited remotely due to the nature of OData entity modifications.