Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2c3g-27ww-4q84

Опубликовано: 12 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.9

Описание

SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.

SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.

EPSS

Процентиль: 23%
0.00076
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9.9
nvd
6 месяцев назад

SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor, creating the risk of full system compromise, undermining the confidentiality, integrity and availability of the system.

CVSS3: 9.9
fstec
6 месяцев назад

Уязвимость функционального модуля RFC-интерфейса программной платформы SAP S/4HANA, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 23%
0.00076
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-94