Логотип exploitDog
bind:CVE-2025-26660
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-26660

Количество 3

Количество 3

nvd логотип

CVE-2025-26660

11 месяцев назад

SAP Fiori applications using the posting library fail to properly configure security settings during the setup process, leaving them at default or inadequately defined. This vulnerability allows an attacker with low privileges to bypass access controls within the application, enabling them to potentially modify data. Confidentiality and Availability are not impacted.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-6xr2-ww2p-m9pg

11 месяцев назад

SAP Fiori applications using the posting library fail to properly configure security settings during the setup process, leaving them at default or inadequately defined. This vulnerability allows an attacker with low privileges to bypass access controls within the application, enabling them to potentially modify data. Confidentiality and Availability are not impacted.

CVSS3: 4.3
EPSS: Низкий
fstec логотип

BDU:2025-03631

11 месяцев назад

Уязвимость платформы проектирования бизнес-приложений SAP Fiori, связанная с обходом авторизации посредством ключа, контролируемого пользователем, позволяющая нарушителю обойти существующие ограничения безопасности

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-26660

SAP Fiori applications using the posting library fail to properly configure security settings during the setup process, leaving them at default or inadequately defined. This vulnerability allows an attacker with low privileges to bypass access controls within the application, enabling them to potentially modify data. Confidentiality and Availability are not impacted.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-6xr2-ww2p-m9pg

SAP Fiori applications using the posting library fail to properly configure security settings during the setup process, leaving them at default or inadequately defined. This vulnerability allows an attacker with low privileges to bypass access controls within the application, enabling them to potentially modify data. Confidentiality and Availability are not impacted.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
fstec логотип
BDU:2025-03631

Уязвимость платформы проектирования бизнес-приложений SAP Fiori, связанная с обходом авторизации посредством ключа, контролируемого пользователем, позволяющая нарушителю обойти существующие ограничения безопасности

CVSS3: 4.3
0%
Низкий
11 месяцев назад

Уязвимостей на страницу