Home
MEDIUM: 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:LDefault status
unaffected
SAP_APPL 600
affected
602
affected
603
affected
604
affected
605
affected
606
affected
616
affected
617
affected
618
affected
S4CORE 100
affected
101
affected
102
affected
Description
SAP Service Parts Management (SPM) does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on Confidentiality, integrity and availability of the application.
Problem types
CWE-862: Missing Authorization
Product status
SAP_APPL 600
602
603
604
605
606
616
617
618
S4CORE 100
101
102