Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-40501

Опубликовано: 10 нояб. 2021
Источник: nvd
CVSS3: 8.1
CVSS2: 5.5
EPSS Низкий

Описание

SAP ABAP Platform Kernel - versions 7.77, 7.81, 7.85, 7.86, does not perform necessary authorization checks for an authenticated business user, resulting in escalation of privileges. That means this business user is able to read and modify data beyond the vulnerable system. However, the attacker can neither significantly reduce the performance of the system nor stop the system.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sap:abap_platform_kernel:7.77:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform_kernel:7.81:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform_kernel:7.85:*:*:*:*:*:*:*
cpe:2.3:a:sap:abap_platform_kernel:7.86:*:*:*:*:*:*:*

EPSS

Процентиль: 40%
0.00182
Низкий

8.1 High

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-862
CWE-862

Связанные уязвимости

github
больше 3 лет назад

SAP ABAP Platform Kernel - versions 7.77, 7.81, 7.85, 7.86, does not perform necessary authorization checks for an authenticated business user, resulting in escalation of privileges. That means this business user is able to read and modify data beyond the vulnerable system. However, the attacker can neither significantly reduce the performance of the system nor stop the system.

EPSS

Процентиль: 40%
0.00182
Низкий

8.1 High

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-862
CWE-862