Within SAP S/4HANA - versions S4CORE 101, 102, 103, 104, 105, 106, SAPSCORE 127, the application business partner extension for Spain/Slovakia does not perform necessary authorization checks for a low privileged authenticated user over the network, resulting in escalation of privileges leading to low impact on confidentiality and integrity of the data.
2022-07-12T21:15:10.143
2024-11-21T07:04:49.053
Modified
CVSSv3.1: 5.4 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:P/A:N
8.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sap | s\/4hana | 101 | Yes |
Application | sap | s\/4hana | 102 | Yes |
Application | sap | s\/4hana | 103 | Yes |
Application | sap | s\/4hana | 104 | Yes |
Application | sap | s\/4hana | 105 | Yes |
Application | sap | s\/4hana | 106 | Yes |
Application | sap | sapscore | 127 | Yes |