5.5
CVE-2021-38164
- EPSS 0.48%
- Veröffentlicht 14.09.2021 12:15:10
- Zuletzt bearbeitet 21.11.2024 06:16:32
- Erkennungen
SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, 618, 700, 720, 730, SAPSCORE - 125, S4CORE, 100, 101, 102, 103, 104, 105, allows a registered attacker to invoke certain functions that would otherwise be restricted to specific users. These functions are normally exposed over the network and once exploited the attacker may be able to view and modify financial accounting data that only a specific user should have access to.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Erp Financial Accounting Version 100
SAP ≫ Erp Financial Accounting Version 101
SAP ≫ Erp Financial Accounting Version 102
SAP ≫ Erp Financial Accounting Version 103
SAP ≫ Erp Financial Accounting Version 104
SAP ≫ Erp Financial Accounting Version 105
SAP ≫ Erp Financial Accounting Version 602
SAP ≫ Erp Financial Accounting Version 603
SAP ≫ Erp Financial Accounting Version 604
SAP ≫ Erp Financial Accounting Version 605
SAP ≫ Erp Financial Accounting Version 606
SAP ≫ Erp Financial Accounting Version 616
SAP ≫ Erp Financial Accounting Version 618
SAP ≫ Erp Financial Accounting Version 700
SAP ≫ Erp Financial Accounting Version 720
SAP ≫ Erp Financial Accounting Version 730
SAP ≫ Erp Financial Accounting Version s4core
SAP ≫ Erp Financial Accounting Version sap_appl_-_600
SAP ≫ Erp Financial Accounting Version sap_fin_-_617
SAP ≫ Erp Financial Accounting Version sapscore_-_125
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.48% | 0.381 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
|
| NIST | 5.5 | 8 | 4.9 |
AV:N/AC:L/Au:S/C:P/I:P/A:N
|
| SAP | 5.4 | 2.8 | 2.5 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405
https://launchpad.support.sap.com/#/notes/3068582