
CVE-2023-40625 – Missing Authorization check in SAP Manage Purchase Contracts App
https://notcve.org/view.php?id=CVE-2023-40625
12 Sep 2023 — S4CORE (Manage Purchase Contracts App) - versions 102, 103, 104, 105, 106, 107, does not perform necessary authorization checks for an authenticated user. This could allow an attacker to perform unintended actions resulting in escalation of privileges which has low impact on confidentiality and integrity with no impact on availibility of the system. S4CORE (Manage Purchase Contracts App): versiones 102, 103, 104, 105, 106, 107, no realiza las comprobaciones de autorización necesarias para un usuario autenti... • https://me.sap.com/notes/3326361 • CWE-862: Missing Authorization •

CVE-2023-35870 – Improper Access Control in SAP S/4HANA (Manage Journal Entry Template)
https://notcve.org/view.php?id=CVE-2023-35870
11 Jul 2023 — When creating a journal entry template in SAP S/4HANA (Manage Journal Entry Template) - versions S4CORE 104, 105, 106, 107, an attacker could intercept the save request and change the template, leading to an impact on confidentiality and integrity of the resource. Furthermore, a standard template could be deleted, hence making the resource temporarily unavailable. • https://me.sap.com/notes/3341211 • CWE-284: Improper Access Control CWE-732: Incorrect Permission Assignment for Critical Resource •