Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-524p-rwpg-qg57

Опубликовано: 09 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

Due to a Missing Authorization Check vulnerability in SAP S/4 HANA Private Cloud (Financials General Ledger), an authenticated attacker with authorization limited to a single company code could read sensitive data and post or modify documents across all company codes. Successful exploitation could result in a high impact to confidentiality and a low impact to integrity, while availability remains unaffected.

Due to a Missing Authorization Check vulnerability in SAP S/4 HANA Private Cloud (Financials General Ledger), an authenticated attacker with authorization limited to a single company code could read sensitive data and post or modify documents across all company codes. Successful exploitation could result in a high impact to confidentiality and a low impact to integrity, while availability remains unaffected.

EPSS

Процентиль: 12%
0.00039
Низкий

7.1 High

CVSS3

Дефекты

CWE-405

Связанные уязвимости

CVSS3: 7.1
nvd
2 месяца назад

Due to a Missing Authorization Check vulnerability in SAP S/4 HANA Private Cloud (Financials General Ledger), an authenticated attacker with authorization limited to a single company code could read sensitive data and post or modify documents across all company codes. Successful exploitation could result in a high impact to confidentiality and a low impact to integrity, while availability remains unaffected.

CVSS3: 7.1
fstec
2 месяца назад

Уязвимость компонента Financials General Ledger программной платформы SAP S/4HANA, позволяющая нарушителю получить доступ на чтение и изменение данных

EPSS

Процентиль: 12%
0.00039
Низкий

7.1 High

CVSS3

Дефекты

CWE-405