VulnerabilityAnalyzed
CVE-2024-41736
Under certain conditions SAP Permit to Work allows an authenticated attacker to access information which would otherwise be restricted causing low impact on the confidentiality of the application.
MEDIUM 4.3EPSS 0.30%
Does this matter?
Lower severity and a low EPSS score (0.30%). Track it; it rarely justifies an emergency change on its own.
Description
Under certain conditions SAP Permit to Work allows an authenticated attacker to access information which would otherwise be restricted causing low impact on the confidentiality of the application.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.30% probability · 22th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- sap/permit to work
- Source
- cna@sap.com
References
- https://me.sap.com/notes/3475427Permissions Required
- https://url.sap/sapsecuritypatchdayVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.