{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-30216","assignerOrgId":"e4686d1a-f260-4930-ac4c-2f5c992778dd","state":"PUBLISHED","assignerShortName":"sap","dateReserved":"2024-03-26T04:09:54.136Z","datePublished":"2024-04-09T01:02:41.597Z","dateUpdated":"2024-08-02T01:25:03.367Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"SAP S/4 HANA (Cash Management)","vendor":"SAP_SE","versions":[{"status":"affected","version":"S4CORE 103"},{"status":"affected","version":"S4CORE 104"},{"status":"affected","version":"S4CORE 105"},{"status":"affected","version":"S4CORE 106"},{"status":"affected","version":"S4CORE 107"},{"status":"affected","version":"S4CORE 108"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, attacker can add notes in the review request with 'completed' status affecting the integrity of the application. Confidentiality and Availability are not impacted.</p>"}],"value":"Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, attacker can add notes in the review request with 'completed' status affecting the integrity of the application. Confidentiality and Availability are not impacted.\n\n"}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-862","description":"CWE-862: Missing Authorization","lang":"eng","type":"CWE"}]}],"providerMetadata":{"orgId":"e4686d1a-f260-4930-ac4c-2f5c992778dd","shortName":"sap","dateUpdated":"2024-04-09T01:02:41.597Z"},"references":[{"url":"https://me.sap.com/notes/3427178"},{"url":"https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364"}],"source":{"discovery":"UNKNOWN"},"title":"Missing Authorization check in SAP S/4 HANA (Cash Management)","x_generator":{"engine":"Vulnogram 0.1.0-dev"}},"adp":[{"title":"CISA ADP Vulnrichment","metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2024-30216","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2024-04-09T19:51:50.635245Z"}}}],"providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-06-04T17:38:58.000Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T01:25:03.367Z"},"title":"CVE Program Container","references":[{"url":"https://me.sap.com/notes/3427178","tags":["x_transferred"]},{"url":"https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html?anchorId=section_370125364","tags":["x_transferred"]}]}]}}