Логотип exploitDog
bind:CVE-2025-25244
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-25244

Количество 3

Количество 3

nvd логотип

CVE-2025-25244

11 месяцев назад

SAP Business Warehouse (Process Chains) allows an attacker to manipulate the process execution due to missing authorization check. An attacker with display authorization for the process chain object could set one or all processes to be skipped. This means corresponding activities, such as data loading, activation, or deletion, will not be executed as initially modeled. This could lead to unexpected results in business reporting leading to a significant impact on integrity. However, there is no impact on confidentiality or availability.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-3p7m-5559-6p23

11 месяцев назад

SAP Business Warehouse (Process Chains) allows an attacker to manipulate the process execution due to missing authorization check. An attacker with display authorization for the process chain object could set one or all processes to be skipped. This means corresponding activities, such as data loading, activation, or deletion, will not be executed as initially modeled. This could lead to unexpected results in business reporting leading to a significant impact on integrity. However, there is no impact on confidentiality or availability.

CVSS3: 5.7
EPSS: Низкий
fstec логотип

BDU:2025-03176

около 1 года назад

Уязвимость компонента Process Chains системы управления данными и аналитики SAP Business Warehouse, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 5.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-25244

SAP Business Warehouse (Process Chains) allows an attacker to manipulate the process execution due to missing authorization check. An attacker with display authorization for the process chain object could set one or all processes to be skipped. This means corresponding activities, such as data loading, activation, or deletion, will not be executed as initially modeled. This could lead to unexpected results in business reporting leading to a significant impact on integrity. However, there is no impact on confidentiality or availability.

CVSS3: 5.7
0%
Низкий
11 месяцев назад
github логотип
GHSA-3p7m-5559-6p23

SAP Business Warehouse (Process Chains) allows an attacker to manipulate the process execution due to missing authorization check. An attacker with display authorization for the process chain object could set one or all processes to be skipped. This means corresponding activities, such as data loading, activation, or deletion, will not be executed as initially modeled. This could lead to unexpected results in business reporting leading to a significant impact on integrity. However, there is no impact on confidentiality or availability.

CVSS3: 5.7
0%
Низкий
11 месяцев назад
fstec логотип
BDU:2025-03176

Уязвимость компонента Process Chains системы управления данными и аналитики SAP Business Warehouse, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

CVSS3: 5.7
0%
Низкий
около 1 года назад

Уязвимостей на страницу