5.5

CVE-2023-32112

Missing Authorization Check in Vendor Master Hierarchy

Vendor Master Hierarchy - versions SAP_APPL 500, SAP_APPL 600, SAP_APPL 602, SAP_APPL 603, SAP_APPL 604, SAP_APPL 605, SAP_APPL 606, SAP_APPL 616, SAP_APPL 617, SAP_APPL 618, S4CORE 100, does not perform necessary authorization checks for an authenticated user to access some of its function. This could lead to modification of data impacting the integrity of the system.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ S4core Version 100
SAP ≫ Vendor Master Hierarchy Version sap_appl_500
SAP ≫ Vendor Master Hierarchy Version sap_appl_600
SAP ≫ Vendor Master Hierarchy Version sap_appl_602
SAP ≫ Vendor Master Hierarchy Version sap_appl_603
SAP ≫ Vendor Master Hierarchy Version sap_appl_604
SAP ≫ Vendor Master Hierarchy Version sap_appl_605
SAP ≫ Vendor Master Hierarchy Version sap_appl_606
SAP ≫ Vendor Master Hierarchy Version sap_appl_616
SAP ≫ Vendor Master Hierarchy Version sap_appl_617
SAP ≫ Vendor Master Hierarchy Version sap_appl_618
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.045
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
SAP 2.8 1.3 1.4
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
Vendor Advisory
https://launchpad.support.sap.com/#/notes/2335198
Broken Link