Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vjh4-v73g-fc8r

Опубликовано: 09 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, attacker can add notes in the review request with 'completed' status affecting the integrity of the application. Confidentiality and Availability are not impacted.

Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, attacker can add notes in the review request with 'completed' status affecting the integrity of the application. Confidentiality and Availability are not impacted.

EPSS

Процентиль: 21%
0.0007
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 4.3
nvd
почти 2 года назад

Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, attacker can add notes in the review request with 'completed' status affecting the integrity of the application. Confidentiality and Availability are not impacted.

EPSS

Процентиль: 21%
0.0007
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862