CVE-2024-4139 Information

Description

Manage Bank Statement ReProcessing Rules does not perform necessary authorization checks for an authenticated user resulting in escalation of privileges. By exploiting this vulnerability an attacker can delete rules of other users affecting the integrity of the application. Confidentiality and Availability are not affected.

Reference

https://me.sap.com/notes/3434666 https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html

Share on: