3 results (0.003 seconds)

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

08 Apr 2025 — SAP Financial Consolidation allows an unauthenticated attacker to gain unauthorized access to the Admin account. The vulnerability arises due to improper authentication mechanisms, due to which there is high impact on the Confidentiality, Integrity & Availability of the application. SAP Financial Consolidation permite que un atacante no autenticado obtenga acceso no autorizado a la cuenta de administrador. La vulnerabilidad surge debido a mecanismos de autenticación inadecuados, lo que afecta gravemente la ... • https://me.sap.com/notes/3572688 • CWE-921: Storage of Sensitive Data in a Mechanism without Access Control •

CVSS: 5.0EPSS: 0%CPEs: 1EXPL: 0

11 Jun 2024 — SAP Financial Consolidation does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. These endpoints are exposed over the network. The vulnerability can exploit resources beyond the vulnerable component. On successful exploitation, an attacker can cause limited impact to confidentiality of the application. SAP Financial Consolidation no codifica suficientemente las entradas controladas por el usuario, lo que genera una vulnerabilidad de Cross-Site Scripting... • https://me.sap.com/notes/3457592 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.1EPSS: 0%CPEs: 1EXPL: 0

11 Jun 2024 — SAP Financial Consolidation allows data to enter a Web application through an untrusted source. These endpoints are exposed over the network and it allows the user to modify the content from the web site. On successful exploitation, an attacker can cause significant impact to confidentiality and integrity of the application. SAP Financial Consolidation permite que los datos ingresen a una aplicación web a través de una fuente que no es de confianza. Estos endpoints están expuestos a través de la red y permi... • https://me.sap.com/notes/3457592 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •