« Volver al listado

CVE-2024-45286

Estado: AplazadaMedia (6.5)—

Due to lack of proper authorization checks when calling user, a function module in obsolete Tobin interface in SAP Production and Revenue Accounting allows unauthorized access that could lead to disclosure of highly sensitive data. There is no impact on integrity or availability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-45286",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-45286",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-10T13:26:08.017203Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cna@sap.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cna@sap.com",
      "affectedData": [
        {
          "vendor": "SAP_SE",
          "product": "SAP Production and Revenue Accounting (Tobin interface)",
          "versions": [
            {
              "status": "affected",
              "version": "S4CEXT 106"
            },
            {
              "status": "affected",
              "version": "S4CEXT 107"
            },
            {
              "status": "affected",
              "version": "S4CEXT 108"
            },
            {
              "status": "affected",
              "version": "IS-PRA 605"
            },
            {
              "status": "affected",
              "version": "IS-PRA 606"
            },
            {
              "status": "affected",
              "version": "IS-PRA 616"
            },
            {
              "status": "affected",
              "version": "IS-PRA 617"
            },
            {
              "status": "affected",
              "version": "IS-PRA 618"
            },
            {
              "status": "affected",
              "version": "IS-PRA 800"
            },
            {
              "status": "affected",
              "version": "IS-PRA 801"
            },
            {
              "status": "affected",
              "version": "IS-PRA 802"
            },
            {
              "status": "affected",
              "version": "IS-PRA 803"
            },
            {
              "status": "affected",
              "version": "IS-PRA 804"
            },
            {
              "status": "affected",
              "version": "IS-PRA 805"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-09-10T04:15:04.950",
  "references": [
    {
      "url": "https://me.sap.com/notes/3488341",
      "source": "cna@sap.com"
    },
    {
      "url": "https://url.sap/sapsecuritypatchday",
      "source": "cna@sap.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cna@sap.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-862"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Due to lack of proper authorization checks when calling user, a function module in obsolete Tobin interface in SAP Production and Revenue Accounting allows unauthorized access that could lead to disclosure of highly sensitive data. There is no impact on integrity or availability."
    },
    {
      "lang": "es",
      "value": "Debido a la falta de controles de autorización adecuados al llamar a un usuario, un módulo de funciones de la interfaz Tobin obsoleta de SAP Production and Revenue Accounting permite el acceso no autorizado que podría dar lugar a la divulgación de datos altamente confidenciales. No hay ningún impacto en la integridad ni en la disponibilidad."
    }
  ],
  "lastModified": "2026-06-17T07:53:57.110",
  "sourceIdentifier": "cna@sap.com"
}