CVE-2024-32730: SAP Enable Now Manager

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

SAP Enable Now Manager does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker with the role 'Learner' could gain access to other user's data in manager which will lead to a high impact to the confidentiality of the application.

Affected products

  • SAP Enable Now Manager: version 1704 only
  • SAP SE SAP Enable Now: version 1704 only

Published 2024-05-14. Last modified 2026-06-17.