VulnerabilityAnalyzed
CVE-2024-22133
SAP Fiori Front End Server - version 605, allows altering of approver details on the read-only field when sending leave request information.
MEDIUM 6.5EPSS 0.30%
Does this matter?
Lower severity and a low EPSS score (0.30%). Track it; it rarely justifies an emergency change on its own.
Description
SAP Fiori Front End Server - version 605, allows altering of approver details on the read-only field when sending leave request information. This could lead to creation of request with incorrect approver causing low impact on Confidentiality and Integrity with no impact on Availability of the application.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.30% probability · 23th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- sap/fiori front end server
- Source
- cna@sap.com
References
- https://me.sap.com/notes/3417399Permissions Required
- https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364Vendor Advisory
- https://me.sap.com/notes/3417399Permissions Required
- https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.