CVE-2024-37176

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/06/2024
Last modified:
09/08/2024

Description

SAP BW/4HANA Transformation and Data Transfer<br /> Process (DTP) allows an authenticated attacker to gain higher access levels<br /> than they should have by exploiting improper authorization checks. This results<br /> in escalation of privileges. It has no impact on the confidentiality of data<br /> but may have low impacts on the integrity and availability of the application.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:bw\/4hana:300:*:*:*:*:*:*:*
cpe:2.3:a:sap:bw\/4hana:400:*:*:*:*:*:*:*
cpe:2.3:a:sap:bw\/4hana:750:*:*:*:*:*:*:*
cpe:2.3:a:sap:bw\/4hana:751:*:*:*:*:*:*:*
cpe:2.3:a:sap:bw\/4hana:752:*:*:*:*:*:*:*
cpe:2.3:a:sap:bw\/4hana:753:*:*:*:*:*:*:*
cpe:2.3:a:sap:bw\/4hana:754:*:*:*:*:*:*:*
cpe:2.3:a:sap:bw\/4hana:755:*:*:*:*:*:*:*
cpe:2.3:a:sap:bw\/4hana:756:*:*:*:*:*:*:*
cpe:2.3:a:sap:bw\/4hana:757:*:*:*:*:*:*:*
cpe:2.3:a:sap:bw\/4hana:758:*:*:*:*:*:*:*
cpe:2.3:a:sap:bw\/4hana:796:*:*:*:*:*:*:*
cpe:2.3:a:sap:bw\/4hana:dw4core_200:*:*:*:*:*:*:*
cpe:2.3:a:sap:bw\/4hana:sap_bw_740:*:*:*:*:*:*:*