CVE-2024-37175

EUVD-2024-36481
SAP CRM WebClient does not
perform necessary authorization check for an authenticated user, resulting in
escalation of privileges. This could allow an attacker to access some sensitive
information.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 53%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
sap_sesap_crm_webclient_ui
S4FND102 ≤
𝑥
≤ S4FND108
ADP
sap_sesap_crm_webclient_ui
WEBCUIF746 ≤
𝑥
≤ WEBCUIF748
ADP
sap_sesap_crm_webclient_ui
WEBCUIF800 ≤
𝑥
≤ WEBCUIF801
ADP