mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-28 18:48:49 +00:00
18 lines
877 B
Markdown
18 lines
877 B
Markdown
### [CVE-2024-25642](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-25642)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the genuine servers to interact with SCC breaking the mutual authentication. Hence, the attacker can intercept the request to view/modify sensitive information. There is no impact on the availability of the system.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- http://seclists.org/fulldisclosure/2024/May/26
|
|
|
|
#### Github
|
|
- https://github.com/fkie-cad/nvd-json-data-feeds
|
|
|