Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-38164

Опубликовано: 14 сент. 2021
Источник: nvd
CVSS3: 5.4
CVSS3: 5.4
CVSS2: 5.5
EPSS Низкий

Описание

SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, 618, 700, 720, 730, SAPSCORE - 125, S4CORE, 100, 101, 102, 103, 104, 105, allows a registered attacker to invoke certain functions that would otherwise be restricted to specific users. These functions are normally exposed over the network and once exploited the attacker may be able to view and modify financial accounting data that only a specific user should have access to.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sap:erp_financial_accounting:100:*:*:*:*:*:*:*
cpe:2.3:a:sap:erp_financial_accounting:101:*:*:*:*:*:*:*
cpe:2.3:a:sap:erp_financial_accounting:102:*:*:*:*:*:*:*
cpe:2.3:a:sap:erp_financial_accounting:103:*:*:*:*:*:*:*
cpe:2.3:a:sap:erp_financial_accounting:104:*:*:*:*:*:*:*
cpe:2.3:a:sap:erp_financial_accounting:105:*:*:*:*:*:*:*
cpe:2.3:a:sap:erp_financial_accounting:602:*:*:*:*:*:*:*
cpe:2.3:a:sap:erp_financial_accounting:603:*:*:*:*:*:*:*
cpe:2.3:a:sap:erp_financial_accounting:604:*:*:*:*:*:*:*
cpe:2.3:a:sap:erp_financial_accounting:605:*:*:*:*:*:*:*
cpe:2.3:a:sap:erp_financial_accounting:606:*:*:*:*:*:*:*
cpe:2.3:a:sap:erp_financial_accounting:616:*:*:*:*:*:*:*
cpe:2.3:a:sap:erp_financial_accounting:618:*:*:*:*:*:*:*
cpe:2.3:a:sap:erp_financial_accounting:700:*:*:*:*:*:*:*
cpe:2.3:a:sap:erp_financial_accounting:720:*:*:*:*:*:*:*
cpe:2.3:a:sap:erp_financial_accounting:730:*:*:*:*:*:*:*
cpe:2.3:a:sap:erp_financial_accounting:s4core:*:*:*:*:*:*:*
cpe:2.3:a:sap:erp_financial_accounting:sap_appl_-_600:*:*:*:*:*:*:*
cpe:2.3:a:sap:erp_financial_accounting:sap_fin_-_617:*:*:*:*:*:*:*
cpe:2.3:a:sap:erp_financial_accounting:sapscore_-_125:*:*:*:*:*:*:*

EPSS

Процентиль: 33%
0.00129
Низкий

5.4 Medium

CVSS3

5.4 Medium

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-862
CWE-862

Связанные уязвимости

github
больше 3 лет назад

SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, 618, 700, 720, 730, SAPSCORE - 125, S4CORE, 100, 101, 102, 103, 104, 105, allows a registered attacker to invoke certain functions that would otherwise be restricted to specific users. These functions are normally exposed over the network and once exploited the attacker may be able to view and modify financial accounting data that only a specific user should have access to.

EPSS

Процентиль: 33%
0.00129
Низкий

5.4 Medium

CVSS3

5.4 Medium

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-862
CWE-862