CVE-2024-37176
published 2024-06-11CVE-2024-37176: SAP BW/4HANA Transformation and Data Transfer Process (DTP) allows an authenticated attacker to gain higher access levels than they should have by exploiting…
PriorityP430medium5.4CVSS 3.1
AVNACLPRLUINSUCNILAL
EPSS
0.28%
19.5th percentile
SAP BW/4HANA Transformation and Data Transfer
Process (DTP) allows an authenticated attacker to gain higher access levels
than they should have by exploiting improper authorization checks. This results
in escalation of privileges. It has no impact on the confidentiality of data
but may have low impacts on the integrity and availability of the application.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | bw_4hana | — | — |
| sap | bw_4hana | — | — |
| sap | bw_4hana | — | — |
| sap | bw_4hana | — | — |
| sap | bw_4hana | — | — |
| sap | bw_4hana | — | — |
| sap | bw_4hana | — | — |
| sap | bw_4hana | — | — |
| sap | bw_4hana | — | — |
| sap | bw_4hana | — | — |
| sap | bw_4hana | — | — |
| sap | bw_4hana | — | — |
| sap | bw_4hana | — | — |
| sap | bw_4hana | — | — |
| sap_se | sap_bw_4hana_transformation_and_data_transfer_process | — | — |
| sap_se | sap_bw_4hana_transformation_and_data_transfer_process | — | — |
| sap_se | sap_bw_4hana_transformation_and_data_transfer_process | — | — |
| sap_se | sap_bw_4hana_transformation_and_data_transfer_process | — | — |
| sap_se | sap_bw_4hana_transformation_and_data_transfer_process | — | — |
| sap_se | sap_bw_4hana_transformation_and_data_transfer_process | — | — |
| sap_se | sap_bw_4hana_transformation_and_data_transfer_process | — | — |
| sap_se | sap_bw_4hana_transformation_and_data_transfer_process | — | — |
| sap_se | sap_bw_4hana_transformation_and_data_transfer_process | — | — |
| sap_se | sap_bw_4hana_transformation_and_data_transfer_process | — | — |
| sap_se | sap_bw_4hana_transformation_and_data_transfer_process | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-06-11
Published