Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-89fv-9763-xj44

Опубликовано: 09 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

SAP Group Reporting Data Collection does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, specific data can be changed via the Enter Package Data app although the user does not have sufficient authorization causing high impact on Integrity of the appliction.

SAP Group Reporting Data Collection does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, specific data can be changed via the Enter Package Data app although the user does not have sufficient authorization causing high impact on Integrity of the appliction.

EPSS

Процентиль: 23%
0.00077
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 6.5
nvd
почти 2 года назад

SAP Group Reporting Data Collection does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, specific data can be changed via the Enter Package Data app although the user does not have sufficient authorization causing high impact on Integrity of the appliction.

CVSS3: 6.5
fstec
почти 2 года назад

Уязвимость компонента Enter Package Data программного обеспечения для сбора финансовых данных для бизнеса SAP Group Reporting Data Collection, позволяющая нарушителю повысить свои привилегии и оказать воздействие на целостность данных

EPSS

Процентиль: 23%
0.00077
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-862