Home
MEDIUM: 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NDefault status
unaffected
S4FND 102
affected
S4FND 103
affected
S4FND 104
affected
S4FND 105
affected
S4FND 106
affected
S4FND 107
affected
S4FND 108
affected
WEBCUIF 701
affected
WEBCUIF 731
affected
WEBCUIF 746
affected
WEBCUIF 747
affected
WEBCUIF 748
affected
WEBCUIF 800
affected
WEBCUIF 801
affected
Description
SAP CRM WebClient does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to access some sensitive information.
Problem types
CWE-862: Missing Authorization
Product status
S4FND 102
S4FND 103
S4FND 104
S4FND 105
S4FND 106
S4FND 107
S4FND 108
WEBCUIF 701
WEBCUIF 731
WEBCUIF 746
WEBCUIF 747
WEBCUIF 748
WEBCUIF 800
WEBCUIF 801