5.5

CVE-2021-38164

SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, 618, 700, 720, 730, SAPSCORE - 125, S4CORE, 100, 101, 102, 103, 104, 105, allows a registered attacker to invoke certain functions that would otherwise be restricted to specific users. These functions are normally exposed over the network and once exploited the attacker may be able to view and modify financial accounting data that only a specific user should have access to.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Erp Financial Accounting Version 100
SAP ≫ Erp Financial Accounting Version 101
SAP ≫ Erp Financial Accounting Version 102
SAP ≫ Erp Financial Accounting Version 103
SAP ≫ Erp Financial Accounting Version 104
SAP ≫ Erp Financial Accounting Version 105
SAP ≫ Erp Financial Accounting Version 602
SAP ≫ Erp Financial Accounting Version 603
SAP ≫ Erp Financial Accounting Version 604
SAP ≫ Erp Financial Accounting Version 605
SAP ≫ Erp Financial Accounting Version 606
SAP ≫ Erp Financial Accounting Version 616
SAP ≫ Erp Financial Accounting Version 618
SAP ≫ Erp Financial Accounting Version 700
SAP ≫ Erp Financial Accounting Version 720
SAP ≫ Erp Financial Accounting Version 730
SAP ≫ Erp Financial Accounting Version s4core
SAP ≫ Erp Financial Accounting Version sap_appl_-_600
SAP ≫ Erp Financial Accounting Version sap_fin_-_617
SAP ≫ Erp Financial Accounting Version sapscore_-_125
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.48% 0.381
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
NIST 5.5 8 4.9
AV:N/AC:L/Au:S/C:P/I:P/A:N
SAP 5.4 2.8 2.5
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405
Vendor Advisory
https://launchpad.support.sap.com/#/notes/3068582
Permissions Required