CVE-2024-27900 describes a missing authorization check in SAP ABAP Platform versions 758 and 795. This vulnerability allows an authenticated business user to alter the privacy setting of job templates from shared to private, making them accessible only to the owner. With a CVSS score of 5.3 (Medium), the attack requires no user interaction and has a low impact on integrity, as it only restricts access to templates. Currently, there is no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
758CPE matchmatch criteria | cpe:2.3:a:sap:abap_platform:758:*:*:*:*:*:*:* | ||
795CPE matchmatch criteria | cpe:2.3:a:sap:abap_platform:795:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.