Логотип exploitDog
bind:CVE-2025-42876
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-42876

Количество 3

Количество 3

nvd логотип

CVE-2025-42876

2 месяца назад

Due to a Missing Authorization Check vulnerability in SAP S/4 HANA Private Cloud (Financials General Ledger), an authenticated attacker with authorization limited to a single company code could read sensitive data and post or modify documents across all company codes. Successful exploitation could result in a high impact to confidentiality and a low impact to integrity, while availability remains unaffected.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-524p-rwpg-qg57

2 месяца назад

Due to a Missing Authorization Check vulnerability in SAP S/4 HANA Private Cloud (Financials General Ledger), an authenticated attacker with authorization limited to a single company code could read sensitive data and post or modify documents across all company codes. Successful exploitation could result in a high impact to confidentiality and a low impact to integrity, while availability remains unaffected.

CVSS3: 7.1
EPSS: Низкий
fstec логотип

BDU:2025-16191

2 месяца назад

Уязвимость компонента Financials General Ledger программной платформы SAP S/4HANA, позволяющая нарушителю получить доступ на чтение и изменение данных

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-42876

Due to a Missing Authorization Check vulnerability in SAP S/4 HANA Private Cloud (Financials General Ledger), an authenticated attacker with authorization limited to a single company code could read sensitive data and post or modify documents across all company codes. Successful exploitation could result in a high impact to confidentiality and a low impact to integrity, while availability remains unaffected.

CVSS3: 7.1
0%
Низкий
2 месяца назад
github логотип
GHSA-524p-rwpg-qg57

Due to a Missing Authorization Check vulnerability in SAP S/4 HANA Private Cloud (Financials General Ledger), an authenticated attacker with authorization limited to a single company code could read sensitive data and post or modify documents across all company codes. Successful exploitation could result in a high impact to confidentiality and a low impact to integrity, while availability remains unaffected.

CVSS3: 7.1
0%
Низкий
2 месяца назад
fstec логотип
BDU:2025-16191

Уязвимость компонента Financials General Ledger программной платформы SAP S/4HANA, позволяющая нарушителю получить доступ на чтение и изменение данных

CVSS3: 7.1
0%
Низкий
2 месяца назад

Уязвимостей на страницу