Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4qcf-w92c-26h6

Опубликовано: 14 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

SAP Enable Now Manager does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker with the role 'Learner' could gain access to other user's data in manager which will lead to a high impact to the confidentiality of the application.

SAP Enable Now Manager does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker with the role 'Learner' could gain access to other user's data in manager which will lead to a high impact to the confidentiality of the application.

EPSS

Процентиль: 31%
0.00115
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 6.5
nvd
больше 1 года назад

SAP Enable Now Manager does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker with the role 'Learner' could gain access to other user's data in manager which will lead to a high impact to the confidentiality of the application.

EPSS

Процентиль: 31%
0.00115
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-862