CVE-2024-37176

MEDIUMCVSS 5.4/10EPSS 0.28%

Last modified

CVE-2024-37176 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. SAP BW/4HANA Transformation and Data Transfer Process (DTP) allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization checks. This results in escalation of privileges. EPSS estimates a 0.28% chance of exploitation in the next 30 days.

Description

SAP BW/4HANA Transformation and Data Transfer Process (DTP) allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization checks. This results in escalation of privileges. It has no impact on the confidentiality of data but may have low impacts on the integrity and availability of the application.

Metrics

CVSS 3.1
5.4/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

EPSS Probability
0.28%

19.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
SapBw\/4hana300
SapBw\/4hana400
SapBw\/4hana750
SapBw\/4hana751
SapBw\/4hana752
SapBw\/4hana753
SapBw\/4hana754
SapBw\/4hana755
SapBw\/4hana756
SapBw\/4hana757
SapBw\/4hana758
SapBw\/4hana796
SapBw\/4hanadw4core_200
SapBw\/4hanasap_bw_740

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2024-37176?
SAP BW/4HANA Transformation and Data Transfer Process (DTP) allows an authenticated attacker to gain higher access levels than they should have by exploiting improper authorization checks. This results in escalation of privileges. It has no impact on the confidentiality of data but may have low impacts on the integrity and availability of the application.
How severe is CVE-2024-37176?
CVE-2024-37176 has a CVSS score of 5.4/10 (MEDIUM severity). The EPSS model estimates a 0.28% probability of exploitation in the next 30 days.
How do I fix CVE-2024-37176?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2024-37176?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST