Description
Due to missing authorization check, attacker with business user account in SAP ABAP Platform - version 758, 795, can change the privacy setting of job templates from shared to private. As a result, the selected template would only be accessible to the owner.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-25092 | Due to missing authorization check, attacker with business user account in SAP ABAP Platform - version 758, 795, can change the privacy setting of job templates from shared to private. As a result, the selected template would only be accessible to the owner. |
References
History
Wed, 26 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap abap Platform |
|
| CPEs | cpe:2.3:a:sap:abap_platform:758:*:*:*:*:*:*:* cpe:2.3:a:sap:abap_platform:795:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sap
Sap abap Platform |
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-04-16T15:40:05.874Z
Reserved: 2024-02-27T06:26:16.787Z
Link: CVE-2024-27900
Updated: 2024-08-02T00:41:55.483Z
Status : Analyzed
Published: 2024-03-12T01:15:49.980
Modified: 2025-02-26T15:15:08.143
Link: CVE-2024-27900
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD