Medium severity4.3NVD Advisory· Published Sep 10, 2024· Updated Jun 17, 2026
CVE-2024-44112
CVE-2024-44112
Description
Due to missing authorization check in SAP for Oil & Gas (Transportation and Distribution), an attacker authenticated as a non-administrative user could call a remote-enabled function which will allow them to delete non-sensitive entries in a user data table. There is no effect on confidentiality or availability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
17600+ 15 more
- (no CPE)range: 600
- cpe:2.3:a:sap:oil_\%\/_gas:600:*:*:*:*:*:*:*
- cpe:2.3:a:sap:oil_\%\/_gas:602:*:*:*:*:*:*:*
- cpe:2.3:a:sap:oil_\%\/_gas:603:*:*:*:*:*:*:*
- cpe:2.3:a:sap:oil_\%\/_gas:604:*:*:*:*:*:*:*
- cpe:2.3:a:sap:oil_\%\/_gas:605:*:*:*:*:*:*:*
- cpe:2.3:a:sap:oil_\%\/_gas:606:*:*:*:*:*:*:*
- cpe:2.3:a:sap:oil_\%\/_gas:617:*:*:*:*:*:*:*
- cpe:2.3:a:sap:oil_\%\/_gas:618:*:*:*:*:*:*:*
- cpe:2.3:a:sap:oil_\%\/_gas:800:*:*:*:*:*:*:*
- cpe:2.3:a:sap:oil_\%\/_gas:802:*:*:*:*:*:*:*
- cpe:2.3:a:sap:oil_\%\/_gas:803:*:*:*:*:*:*:*
- cpe:2.3:a:sap:oil_\%\/_gas:804:*:*:*:*:*:*:*
- cpe:2.3:a:sap:oil_\%\/_gas:805:*:*:*:*:*:*:*
- cpe:2.3:a:sap:oil_\%\/_gas:806:*:*:*:*:*:*:*
- cpe:2.3:a:sap:oil_\%\/_gas:807:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- url.sap/sapsecuritypatchdaynvdPatch
- me.sap.com/notes/3505293nvdPermissions Required
News mentions
0No linked articles in our index yet.