CVE-2024-32731

SAP My Travel Requests does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker can upload a malicious attachment to a business trip request which will lead to a low impact on the confidentiality, integrity and availability of the application. 
Configurations

No configuration.

History

No history.

Information

Published : 2024-05-14 16:17

Updated : 2024-05-14 19:17


NVD link : CVE-2024-32731

Mitre link : CVE-2024-32731

CVE.ORG link : CVE-2024-32731


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization