6 results (0.018 seconds)

CVSS: 5.4EPSS: 0%CPEs: 6EXPL: 0

S4CORE (Manage Purchase Contracts App) - versions 102, 103, 104, 105, 106, 107, does not perform necessary authorization checks for an authenticated user. This could allow an attacker to perform unintended actions resulting in escalation of privileges which has low impact on confidentiality and integrity with no impact on availibility of the system. S4CORE (Manage Purchase Contracts App): versiones 102, 103, 104, 105, 106, 107, no realiza las comprobaciones de autorización necesarias para un usuario autenticado. Esto podría permitir a un atacante realizar acciones no intencionadas, lo que resulta en una escalada de privilegios que tiene un bajo impacto en la confidencialidad y la integridad sin impacto en la disponibilidad del sistema. • https://me.sap.com/notes/3326361 https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html • CWE-862: Missing Authorization •

CVSS: 7.3EPSS: 0%CPEs: 4EXPL: 0

When creating a journal entry template in SAP S/4HANA (Manage Journal Entry Template) - versions S4CORE 104, 105, 106, 107, an attacker could intercept the save request and change the template, leading to an impact on confidentiality and integrity of the resource. Furthermore, a standard template could be deleted, hence making the resource temporarily unavailable. • https://me.sap.com/notes/3341211 https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html • CWE-284: Improper Access Control CWE-732: Incorrect Permission Assignment for Critical Resource •

CVSS: 9.1EPSS: 0%CPEs: 14EXPL: 4

DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 710, 2011_1_752, 2020, SAPSCORE 125, S4CORE 102, 102, 103, 104, 105, allows an attacker with access to highly privileged account to execute manipulated query in NDZT tool to gain access to Superuser account, leading to SQL Injection vulnerability, that highly impacts systems Confidentiality, Integrity and Availability. DMIS Mobile Plug-In o SAP S/4HANA, versiones - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 710, 2011_1_752, 2020, SAPSCORE 125, S4CORE 102, 102, 103, 104, 105, permite a un atacante con acceso a una cuenta altamente privilegiada ejecutar una consulta manipulada en la herramienta NDZT para conseguir acceso a la cuenta Superuser, conllevando a una vulnerabilidad de Inyección SQL, que presenta un gran impacto en la Confidencialidad, Integridad y Disponibilidad de los sistemas SAP Netweaver suffers from a remote ADBC SQL injection vulnerability in IUUC_RECON_RC_COUNT_TABLE_BIG. Other software and various versions are also affected. • http://packetstormsecurity.com/files/165303/SAP-Netweaver-IUUC_RECON_RC_COUNT_TABLE_BIG-SQL-Injection.html http://packetstormsecurity.com/files/165304/SAP-Netweaver-IUUC_RECON_RC_COUNT_TABLE_BIG-ABAP-Code-Injection.html http://seclists.org/fulldisclosure/2021/Dec/35 http://seclists.org/fulldisclosure/2021/Dec/36 https://launchpad.support.sap.com/#/notes/3078312 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=582222806 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 8.1EPSS: 0%CPEs: 13EXPL: 0

Statutory Reporting for Insurance Companies in SAP ERP (EA-FINSERV versions - 600, 603, 604, 605, 606, 616, 617, 618, 800 and S4CORE versions 101, 102, 103, 104) does not execute the required authorization checks for an authenticated user, allowing an attacker to view and tamper with certain restricted data leading to Missing Authorization Check. Statutory Reporting de Insurance Companies en SAP ERP (EA-FINSERV versiones - 600, 603, 604, 605, 606, 616, 617, 618, 800 y S4CORE versiones 101, 102, 103, 104) no ejecuta las comprobaciones de autorización requeridas para un usuario autenticado, que permite a un atacante visualizar y manipular determinados datos restringidos conllevando a una Falta de Verificación de Autorización • https://launchpad.support.sap.com/#/notes/2906996 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=547426775 • CWE-862: Missing Authorization •

CVSS: 8.8EPSS: 0%CPEs: 5EXPL: 0

The use of an admin backend report within SAP Master Data Governance, versions - S4CORE 101, S4FND 102, 103, 104, SAP_BS_FND 748; allows an attacker to execute crafted database queries, exposing the backend database, leading to SQL Injection. El uso de un reporte del backend de administración dentro de SAP Master Data Governance, versiones - S4CORE 101, S4FND 102, 103, 104, SAP_BS_FND 748; permite al atacante ejecutar consultas de base de datos diseñadas, exponiendo la base de datos del backend, conllevando a una Inyección SQL. • https://launchpad.support.sap.com/#/notes/2908560 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=545396222 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •