Vulnerabilities > CVE-2024-39592 - Missing Authorization vulnerability in SAP S4Core and S4Coreop
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This allows an attacker to read sensitive information causing high impact on the confidentiality of the application.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 7 |