Security Advisory

CVE-2024-27900

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-03-12 00:44:15
Last updated 2025-04-16 15:40:05
Assigner sap
State PUBLISHED

Description

Due to missing authorization check, attacker with business user account in SAP ABAP Platform - version 758, 795, can change the privacy setting of job templates from shared to private. As a result, the selected template would only be accessible to the owner.