CVE-2024-25643
Last modified
CVE-2024-25643 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The SAP Fiori app (My Overtime Request) - version 605, does not perform the necessary authorization checks for an authenticated user which may result in an escalation of privileges. It is possible to manipulate the URLs of data requests to access information that the user should not have access to. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
The SAP Fiori app (My Overtime Request) - version 605, does not perform the necessary authorization checks for an authenticated user which may result in an escalation of privileges. It is possible to manipulate the URLs of data requests to access information that the user should not have access to. There is no impact on integrity and availability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Fiori | 605 |
References
- https://me.sap.com/notes/3237638Permissions Required
- https://me.sap.com/notes/3237638Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-25643?
How severe is CVE-2024-25643?
How do I fix CVE-2024-25643?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-25638dnsjava is an implementation of DNS in Java. Records in DNS …8.9
- CVE-2024-25639Khoj is an application that creates personal AI agents. The …7.5
- CVE-2024-2564A vulnerability was found in PandaXGO PandaX up to 20240310 …7.3
- CVE-2024-25640Iris is a web collaborative platform that helps incident res…5.4
- CVE-2024-25641Cacti provides an operational monitoring and fault managemen…7.2
- CVE-2024-25642Due to improper validation of certificate in SAP Cloud Conne…7.4
- CVE-2024-25644Under certain conditions SAP NetWeaver WSRM - version 7.50, …5.3
- CVE-2024-25645Under certain condition SAP NetWeaver (Enterprise Portal) - …5.3
- CVE-2024-25646Due to improper validation, SAP BusinessObject Business Inte…6.5
- CVE-2024-25647Incorrect default permissions for some Intel(R) Binary Confi…6.7
- CVE-2024-25648A use-after-free vulnerability exists in the way Foxit Reade…8.8
- CVE-2024-25649In Delinea PAM Secret Server 11.4, it is possible for an att…6.7
Are you affected by CVE-2024-25643?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
