Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-40625


S4CORE (Manage Purchase Contracts App) - versions 102, 103, 104, 105, 106, 107, does not perform necessary authorization checks for an authenticated user. This could allow an attacker to perform unintended actions resulting in escalation of privileges which has low impact on confidentiality and integrity with no impact on availibility of the system.


Published

2023-09-12T03:15:14.147

Last Modified

2024-11-21T08:19:50.863

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-862

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap s4core 102 Yes
Application sap s4core 103 Yes
Application sap s4core 104 Yes
Application sap s4core 105 Yes
Application sap s4core 106 Yes
Application sap s4core 107 Yes

References