2024-10-20 02:03:20 +00:00

64 lines
2.1 KiB
JSON

{
"id": "CVE-2024-44115",
"sourceIdentifier": "cna@sap.com",
"published": "2024-09-10T03:15:03.293",
"lastModified": "2024-09-10T12:09:50.377",
"vulnStatus": "Undergoing Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "The RFC enabled function module allows a low privileged user to add URLs to any user's workplace favourites. This vulnerability could be utilized to identify usernames and access information about targeted user's workplaces, and nodes. There is low impact on integrity of the application"
},
{
"lang": "es",
"value": "El m\u00f3dulo de funci\u00f3n habilitado por RFC permite que un usuario con pocos privilegios agregue URL a los favoritos del lugar de trabajo de cualquier usuario. Esta vulnerabilidad podr\u00eda utilizarse para identificar nombres de usuario y acceder a informaci\u00f3n sobre los lugares de trabajo y los nodos del usuario objetivo. El impacto en la integridad de la aplicaci\u00f3n es bajo."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "cna@sap.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "LOW",
"availabilityImpact": "NONE",
"baseScore": 4.3,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.8,
"impactScore": 1.4
}
]
},
"weaknesses": [
{
"source": "cna@sap.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-862"
}
]
}
],
"references": [
{
"url": "https://me.sap.com/notes/3488039",
"source": "cna@sap.com"
},
{
"url": "https://url.sap/sapsecuritypatchday",
"source": "cna@sap.com"
}
]
}