CVE-2024-22132
Published Feb 13, 2024
Last updated a month ago
Overview
- Description
- SAP IDES ECC-systems contain code that permits the execution of arbitrary program code of user's choice.An attacker can therefore control the behaviour of the system by executing malicious code which can potentially escalate privileges with low impact on confidentiality, integrity and availability of the system.
- Source
- cna@sap.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 6.3
- Impact score
- 3.4
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Severity
- MEDIUM
Weaknesses
- cna@sap.com
- CWE-78
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:sap:ides_ecc:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C1F3ABB7-AE38-4215-9770-E9AD0AAB674A" } ], "operator": "OR" } ] } ]