CVE-2024-25642

CVSS V2 None CVSS V3 None
Description
Due to improper validation of certificate in SAP Cloud Connector - version 2.0, attacker can impersonate the genuine servers to interact with SCC breaking the mutual authentication. Hence, the attacker can intercept the request to view/modify sensitive information. There is no impact on the availability of the system.
Overview
  • CVE ID
  • CVE-2024-25642
  • Assigner
  • sap
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-02-13T02:44:20.284Z
  • Last Modified Date
  • 2024-02-13T02:44:20.284Z
History
Created Old Value New Value Data Type Notes
2024-06-26 12:47:17 Added to TrackCVE