Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4c58-m4cg-6h2f

Опубликовано: 14 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user with low privileges could guess and enumerate the content shown, beyond their authorized scope. This leads to disclosure of sensitive information causing a high impact on confidentiality, while integrity and availability are unaffected.

During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user with low privileges could guess and enumerate the content shown, beyond their authorized scope. This leads to disclosure of sensitive information causing a high impact on confidentiality, while integrity and availability are unaffected.

EPSS

Процентиль: 19%
0.00269
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-204

Связанные уязвимости

CVSS3: 6.5
nvd
4 месяца назад

During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user with low privileges could guess and enumerate the content shown, beyond their authorized scope. This leads to disclosure of sensitive information causing a high impact on confidentiality, while integrity and availability are unaffected.

CVSS3: 6.5
fstec
4 месяца назад

Уязвимость программного обеспечения управления ресурсами человеческого капитала в организации SAP Human Capital Management (HCM), связанная с несоответствием ответов на входящие запросы, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 19%
0.00269
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-204