Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cqf6-x4h9-93wj

Опубликовано: 13 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extension for Spain/Slovakia does not perform necessary authorization checks for a low privileged authenticated user over the network, resulting in escalation of privileges leading to low impact on confidentiality and integrity of the data.

Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extension for Spain/Slovakia does not perform necessary authorization checks for a low privileged authenticated user over the network, resulting in escalation of privileges leading to low impact on confidentiality and integrity of the data.

EPSS

Процентиль: 35%
0.00144
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 5.4
nvd
больше 3 лет назад

Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extension for Spain/Slovakia does not perform necessary authorization checks for a low privileged authenticated user over the network, resulting in escalation of privileges leading to low impact on confidentiality and integrity of the data.

CVSS3: 5.4
fstec
больше 3 лет назад

Уязвимость компонента Application Business Partner Extension программной платформы SAP S/4HANA, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 35%
0.00144
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-862