Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v5mq-3g8r-vp97

Опубликовано: 12 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

Due to a missing authorization check in the ABAP Platform, an authenticated user with elevated privileges could bypass authorization restrictions for common transactions by leveraging the SQL Console. This could enable an attacker to access and read the contents of database tables without proper authorization, leading to a significant compromise of data confidentiality. However, the integrity and availability of the system remain unaffected.

Due to a missing authorization check in the ABAP Platform, an authenticated user with elevated privileges could bypass authorization restrictions for common transactions by leveraging the SQL Console. This could enable an attacker to access and read the contents of database tables without proper authorization, leading to a significant compromise of data confidentiality. However, the integrity and availability of the system remain unaffected.

EPSS

Процентиль: 24%
0.00312
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 4.9
nvd
около 1 года назад

Due to a missing authorization check in the ABAP Platform, an authenticated user with elevated privileges could bypass authorization restrictions for common transactions by leveraging the SQL Console. This could enable an attacker to access and read the contents of database tables without proper authorization, leading to a significant compromise of data confidentiality. However, the integrity and availability of the system remain unaffected.

CVSS3: 4.9
fstec
около 1 года назад

Уязвимость программной интеграционной платформы SAP NetWeaver ABAP, связанная с отсутствием авторизации, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 24%
0.00312
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-862