cve/2023/CVE-2023-24524.md

18 lines
855 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2023-24524](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24524)
![](https://img.shields.io/static/v1?label=Product&message=S%2F4%20HANA%20(Map%20Treasury%20Correspondence%20Format%20Data)&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%20104%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-862%3A%20Missing%20Authorization&color=brighgreen)
### Description
SAP S/4 HANA Map Treasury Correspondence Format Data does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to delete the data with a high impact to availability.
### POC
#### Reference
- https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
#### Github
No PoCs found on GitHub currently.