Skip links

Missing confirmation prompt in CATT function modules, SAP security note 751806

Description

Authorizations do not sufficiently protect two CATT function modules from misuse.

Available fix and Supported packages

  • SAP_APPL | 31I | 31I
  • SAP_APPL | 40B | 40B
  • SAP_APPL | 45B | 45B
  • SAP_BASIS | 46B | 46D
  • SAP_BASIS | 610 | 640
  • SAP_APPL 31I | SAPKH31IB9 |
  • SAP_APPL 40B | SAPKH40B89 |
  • SAP_APPL 45B | SAPKH45B67 |
  • SAP_BASIS 46C | SAPKB46C48 |
  • SAP_BASIS 46B | SAPKB46B57 |
  • SAP_BASIS 640 | SAPKB64005 |
  • SAP_BASIS 46D | SAPKB46D38 |
  • SAP_BASIS 610 | SAPKB61041 |
  • SAP_BASIS 620 | SAPKB62043 |

Affected component

    BC-TWB-TST-CAT
    CATT Computer Aided Test Tool

CVSS

Score: 0

Exploit

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/751806

TAGS

#

How to detect over 4100 vulnerabilities in SAP Systems?

More to explorer

SAP Cloud Connector Certificate Validation Issue

Date of Release: February 13, 2024 Advisory ID: CVE-2024-25642 Affected Software: SAP Cloud Connector Versions Affected: 2.15.0 to 2.16.1 Vulnerability Summary:A critical vulnerability,