Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9h2g-5fp5-mw6q

Опубликовано: 14 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

SAP GRC Access control Emergency Access Management allows an authenticated attacker to access a Firefighter session even after it is closed in Firefighter Logon Pad. This attack can be launched only within the firewall. On successful exploitation the attacker can gain access to admin session and completely compromise the application.

SAP GRC Access control Emergency Access Management allows an authenticated attacker to access a Firefighter session even after it is closed in Firefighter Logon Pad. This attack can be launched only within the firewall. On successful exploitation the attacker can gain access to admin session and completely compromise the application.

EPSS

Процентиль: 60%
0.00403
Низкий

7.5 High

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 7.5
nvd
больше 3 лет назад

SAP GRC Access control Emergency Access Management allows an authenticated attacker to access a Firefighter session even after it is closed in Firefighter Logon Pad. This attack can be launched only within the firewall. On successful exploitation the attacker can gain access to admin session and completely compromise the application.

EPSS

Процентиль: 60%
0.00403
Низкий

7.5 High

CVSS3

Дефекты

CWE-287