CVE-2024-42376: SAP Shared Service Framework
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
SAP Shared Service Framework does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. On successful exploitation, an attacker can cause a high impact on confidentiality of the application.
Affected products
- SAP Shared Service Framework: version sap_bs_fnd_702 only; version sap_bs_fnd_731 only; version sap_bs_fnd_746 only; version sap_bs_fnd_747 only; version sap_bs_fnd_748 only
Published 2024-08-13. Last modified 2026-06-17.