Vulnerability CVE-2024-44115


Published: 2024-09-10

Description:
The RFC enabled function module allows a low privileged user to add URLs to any user's workplace favourites. This vulnerability could be utilized to identify usernames and access information about targeted user's workplaces, and nodes. There is low impact on integrity of the application

Type:

CWE-862

(Missing Authorization)

 References:
https://me.sap.com/notes/3488039
https://url.sap/sapsecuritypatchday

Copyright 2026, cxsecurity.com

 

Back to Top