Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5558-5q6p-4jgw

Опубликовано: 11 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application function to perform actions which they would not normally be permitted to perform. Depending on the function executed, the attack can can have limited impact on confidentiality and integrity of non-critical user or application data and application availability.

In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application function to perform actions which they would not normally be permitted to perform. Depending on the function executed, the attack can can have limited impact on confidentiality and integrity of non-critical user or application data and application availability.

EPSS

Процентиль: 84%
0.02251
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 6
nvd
почти 3 года назад

In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application function to perform actions which they would not normally be permitted to perform. Depending on the function executed, the attack can can have limited impact on confidentiality and integrity of non-critical user or application data and application availability.

EPSS

Процентиль: 84%
0.02251
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-94