SAP ERP (HCM Travel Management), versions - 600, 602, 603, 604, 605, 606, 607, 608, allows an authenticated but unauthorized attacker to read, modify and settle trips, resulting in escalation of privileges, due to Missing Authorization Check.
2020-08-12T14:15:14.610
2024-11-21T05:35:28.020
Modified
CVSSv3.1: 8.1 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:N
8.0
4.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | sap | hcm_travel_management | 600 | Yes |
| Application | sap | hcm_travel_management | 602 | Yes |
| Application | sap | hcm_travel_management | 603 | Yes |
| Application | sap | hcm_travel_management | 604 | Yes |
| Application | sap | hcm_travel_management | 605 | Yes |
| Application | sap | hcm_travel_management | 606 | Yes |
| Application | sap | hcm_travel_management | 607 | Yes |
| Application | sap | hcm_travel_management | 608 | Yes |