CVE-2023-24528: SAP Fiori

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

SAP Fiori apps for Travel Management in SAP ERP (My Travel Requests) - version 600, allows an authenticated attacker to exploit a certain misconfigured application endpoint to view sensitive data. This endpoint is normally exposed over the network and successful exploitation can lead to exposure of data like travel documents.

Affected products

  • SAP Fiori: version 600 only

Published 2023-02-14. Last modified 2026-06-17.