Home
MEDIUM: 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NDefault status
unaffected
S4HCMRXX 100
affected
101
affected
102
affected
SAP_HRRXX 600
affected
604
affected
608
affected
Description
Due to a missing authorization check in SAP Business Analytics and SAP Content Management, an authenticated user could make unauthorized calls to certain remote function modules, potentially accessing sensitive information beyond their intended permissions. This vulnerability affects confidentiality, with no impact on integrity and availability.
Problem types
CWE-862: Missing Authorization
Product status
S4HCMRXX 100
101
102
SAP_HRRXX 600
604
608