VYPR
Medium severity4.3NVD Advisory· Published Sep 10, 2024· Updated Jun 17, 2026

CVE-2024-44112

CVE-2024-44112

Description

Due to missing authorization check in SAP for Oil & Gas (Transportation and Distribution), an attacker authenticated as a non-administrative user could call a remote-enabled function which will allow them to delete non-sensitive entries in a user data table. There is no effect on confidentiality or availability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

17
  • SAP/Oil \%\/ Gascpe-rescue16 versions
    600+ 15 more
    • (no CPE)range: 600
    • cpe:2.3:a:sap:oil_\%\/_gas:600:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:oil_\%\/_gas:602:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:oil_\%\/_gas:603:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:oil_\%\/_gas:604:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:oil_\%\/_gas:605:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:oil_\%\/_gas:606:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:oil_\%\/_gas:617:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:oil_\%\/_gas:618:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:oil_\%\/_gas:800:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:oil_\%\/_gas:802:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:oil_\%\/_gas:803:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:oil_\%\/_gas:804:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:oil_\%\/_gas:805:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:oil_\%\/_gas:806:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:oil_\%\/_gas:807:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.