Description
Due to a Missing Authorization Check in SAP Business Warehouse (Service API), an authenticated attacker could perform unauthorized actions via an affected RFC function module. Successful exploitation could enable unauthorized configuration and control changes, potentially disrupting request processing and causing denial of service. This results in low impact on integrity and high impact on availability, while confidentiality remains unaffected.
Problem types
CWE-862: Missing Authorization
Product status
DW4CORE 200
300
400
PI_BASIS 2006_1_700
701
702
730
731
740
SAP_BW 750
751
752
753
754
755
756
757
758
816