Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-42qx-rv8j-r8f3

Опубликовано: 15 сент. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges acquired, an attacker could abuse functionality restricted to a particular user group as well as read, modify or delete restricted data.

SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges acquired, an attacker could abuse functionality restricted to a particular user group as well as read, modify or delete restricted data.

EPSS

Процентиль: 37%
0.00162
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-862
CWE-863

Связанные уязвимости

CVSS3: 9.8
nvd
больше 2 лет назад

SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation of privileges. Depending on the application and the level of privileges acquired, an attacker could abuse functionality restricted to a particular user group as well as read, modify or delete restricted data.

CVSS3: 9.8
fstec
больше 2 лет назад

Уязвимость библиотеки SAP CommonCryptoLib, связанная с недостатками процедуры авторизации, позволяющая нарушителю читать, изменять или удалять данные с ограниченным доступом

EPSS

Процентиль: 37%
0.00162
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-862
CWE-863