CVE-2023-32112
Missing Authorization Check in Vendor Master Hierarchy
Severity Score
5.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Vendor Master Hierarchy - versions SAP_APPL 500, SAP_APPL 600, SAP_APPL 602, SAP_APPL 603, SAP_APPL 604, SAP_APPL 605, SAP_APPL 606, SAP_APPL 616, SAP_APPL 617, SAP_APPL 618, S4CORE 100, does not perform necessary authorization checks for an authenticated user to access some of its function. This could lead to modification of data impacting the integrity of the system.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-05-03 CVE Reserved
- 2023-05-09 CVE Published
- 2023-05-09 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-862: Missing Authorization
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://launchpad.support.sap.com/#/notes/2335198 | Broken Link |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | 2023-05-15 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sap Search vendor "Sap" | S4core Search vendor "Sap" for product "S4core" | 100 Search vendor "Sap" for product "S4core" and version "100" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Vendor Master Hierarchy Search vendor "Sap" for product "Vendor Master Hierarchy" | sap_appl_500 Search vendor "Sap" for product "Vendor Master Hierarchy" and version "sap_appl_500" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Vendor Master Hierarchy Search vendor "Sap" for product "Vendor Master Hierarchy" | sap_appl_600 Search vendor "Sap" for product "Vendor Master Hierarchy" and version "sap_appl_600" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Vendor Master Hierarchy Search vendor "Sap" for product "Vendor Master Hierarchy" | sap_appl_602 Search vendor "Sap" for product "Vendor Master Hierarchy" and version "sap_appl_602" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Vendor Master Hierarchy Search vendor "Sap" for product "Vendor Master Hierarchy" | sap_appl_603 Search vendor "Sap" for product "Vendor Master Hierarchy" and version "sap_appl_603" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Vendor Master Hierarchy Search vendor "Sap" for product "Vendor Master Hierarchy" | sap_appl_604 Search vendor "Sap" for product "Vendor Master Hierarchy" and version "sap_appl_604" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Vendor Master Hierarchy Search vendor "Sap" for product "Vendor Master Hierarchy" | sap_appl_605 Search vendor "Sap" for product "Vendor Master Hierarchy" and version "sap_appl_605" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Vendor Master Hierarchy Search vendor "Sap" for product "Vendor Master Hierarchy" | sap_appl_606 Search vendor "Sap" for product "Vendor Master Hierarchy" and version "sap_appl_606" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Vendor Master Hierarchy Search vendor "Sap" for product "Vendor Master Hierarchy" | sap_appl_616 Search vendor "Sap" for product "Vendor Master Hierarchy" and version "sap_appl_616" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Vendor Master Hierarchy Search vendor "Sap" for product "Vendor Master Hierarchy" | sap_appl_617 Search vendor "Sap" for product "Vendor Master Hierarchy" and version "sap_appl_617" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Vendor Master Hierarchy Search vendor "Sap" for product "Vendor Master Hierarchy" | sap_appl_618 Search vendor "Sap" for product "Vendor Master Hierarchy" and version "sap_appl_618" | - |
Affected
|