Home
MEDIUM: 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NDefault status
unaffected
SAP_BASIS 700
affected
SAP_BASIS 701
affected
SAP_BASIS 702
affected
SAP_BASIS 731
affected
SAP_BASIS 740
affected
SAP_BASIS 750
affected
SAP_BASIS 751
affected
SAP_BASIS 752
affected
SAP_BASIS 753
affected
SAP_BASIS 754
affected
SAP_BASIS 755
affected
SAP_BASIS 756
affected
SAP_BASIS 757
affected
SAP_BASIS 758
affected
Description
A Missing Authorization Check vulnerability exists in the Virus Scanner Interface of SAP NetWeaver Application Server ABAP. Because of this, an attacker authenticated as a non-administrative user can initiate a transaction, allowing them to access but not modify non-sensitive data without further authorization and with no effect on availability.
Problem types
CWE-862: Missing Authorization
Product status
SAP_BASIS 700
SAP_BASIS 701
SAP_BASIS 702
SAP_BASIS 731
SAP_BASIS 740
SAP_BASIS 750
SAP_BASIS 751
SAP_BASIS 752
SAP_BASIS 753
SAP_BASIS 754
SAP_BASIS 755
SAP_BASIS 756
SAP_BASIS 757
SAP_BASIS 758