CVE-2024-39591: SAP Document Builder
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
SAP Document Builder does not perform necessary authorization checks for one of the function modules resulting in escalation of privileges causing low impact on confidentiality of the application.
Affected products
- SAP Document Builder: version s4fnd_102 only; version s4fnd_103 only; version s4fnd_104 only; version s4fnd_105 only; version s4fnd_106 only; version s4fnd_107 only; …
Published 2024-08-13. Last modified 2026-06-17.