CVE-2024-47581: Missing Authorization check in SAP HCM (Approve Timesheets version 4)

4.3 CVSS

Description

SAP HCM Approve Timesheets Version 4 application does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.There is low impact on integrity of the application. Confidentiality and availibility are not impacted.

Classification

CVE ID: CVE-2024-47581

CVSS Base Severity: MEDIUM

CVSS Base Score: 4.3

Affected Products

Vendor: SAP_SE

Product: SAP HCM

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.44% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://me.sap.com/notes/3522332
https://url.sap/sapsecuritypatchday

Timeline