Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mwg4-fjw2-7rjc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SAP S/4 HANA (Fiori UI for General Ledger Accounting), versions 103, 104, does not perform necessary authorization checks for an authenticated user working with attachment service, allowing the attacker to delete attachments due to Missing Authorization Check.

SAP S/4 HANA (Fiori UI for General Ledger Accounting), versions 103, 104, does not perform necessary authorization checks for an authenticated user working with attachment service, allowing the attacker to delete attachments due to Missing Authorization Check.

EPSS

Процентиль: 34%
0.00136
Низкий

Связанные уязвимости

CVSS3: 4.3
nvd
больше 5 лет назад

SAP S/4 HANA (Fiori UI for General Ledger Accounting), versions 103, 104, does not perform necessary authorization checks for an authenticated user working with attachment service, allowing the attacker to delete attachments due to Missing Authorization Check.

CVSS3: 5.4
fstec
больше 5 лет назад

Уязвимость платформы бизнес-аналитики SAP Business Objects Business Intelligence Platform, существующая из-за непринятия мер по защите структуры веб-страницы, позволяющая нарушителю провести XSS-атаки

EPSS

Процентиль: 34%
0.00136
Низкий