CyberzSOC

Publication detail
← Back to advisories & guidance

2024-079: Critical SAP Authentication Bypass Vulnerability ↗ source

August 14, 2024 CERT-EU Advisory

Summary

This flaw allows remote attackers to bypass authentication mechanisms, potentially leading to full system compromise. The vulnerability has a CVSS score of 9.8, highlighting its severity. CVE-2024-41730 is a “missing authentication check” vulnerability. If Single Sign-On is enabled for Enterprise authentication, an attacker can exploit a REST endpoint to obtain a logon token and compromise the system entirely, affecting confidentiality, integrity, and availability [1,2]. CERT-EU strongly advises applying the security patches provided by SAP immediately to mitigate this critical vulnerability.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-41730 9.8 Critical SAP_SE SAP BusinessObjects Business Intelligence Platform In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a lo…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.