Due to missing authorization check, attacker with business user account in SAP ABAP Platform - version 758, 795, can change the privacy setting of job templates from shared to private. As a result, the selected template would only be accessible to the owner.
2024-03-12T01:15:49.980
2025-02-26T16:32:47.043
Analyzed
CVSSv3.1: 4.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sap | abap_platform | 758 | Yes |
Application | sap | abap_platform | 795 | Yes |