Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pm6j-4v44-3wr7

Опубликовано: 09 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 3.1

Описание

Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and perform activities that are otherwise restricted, resulting in a low impact on the integrity of the application. Confidentiality and availability are not impacted.

Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and perform activities that are otherwise restricted, resulting in a low impact on the integrity of the application. Confidentiality and availability are not impacted.

EPSS

Процентиль: 5%
0.00023
Низкий

3.1 Low

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 3.1
nvd
5 месяцев назад

Due to missing authorization checks, SAP HCM My Timesheet Fiori 2.0 application allows an authenticated attacker with in-depth system knowledge to escalate privileges and perform activities that are otherwise restricted, resulting in a low impact on the integrity of the application. Confidentiality and availability are not impacted.

CVSS3: 3.1
fstec
10 месяцев назад

Уязвимость компонента My Timesheet Fiori 2.0 программного обеспечения для управления персоналом SAP HCM, позволяющая нарушителю повысить привилегии

EPSS

Процентиль: 5%
0.00023
Низкий

3.1 Low

CVSS3

Дефекты

CWE-862