Home
MEDIUM: 4.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:LDefault status
unaffected
S4CORE 105
affected
106
affected
107
affected
108
affected
109
affected
FI-CA 606
affected
616
affected
617
affected
618
affected
Description
Due to a missing authorization check, SAP S/4HANA (Private Cloud and On-Premise) allows an authenticated user to delete files on the operating system and gain unauthorized control over file operations which could leads to no impact on Confidentiality, Low impact on Integrity and Availability of the application.
Problem types
CWE-862: Missing Authorization
Product status
S4CORE 105
106
107
108
109
FI-CA 606
616
617
618