Home
MEDIUM: 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NDefault status
unaffected
S4CORE 104
affected
105
affected
106
affected
107
affected
108
affected
Description
SAP Manage Processing Rules (For Bank Statement) allows an attacker with basic privileges to edit shared rules of any user by tampering the request parameter. Due to missing authorization check, the attacker can edit rules that should be restricted, compromising the integrity of the application.
Problem types
CWE-862: Missing Authorization
Product status
S4CORE 104
105
106
107
108