Home
MEDIUM: 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NDefault status
unaffected
S4HCMRXX 100
affected
101
affected
102
affected
SAP_HRRXX 600
affected
604
affected
608
affected
Description
During authorization checks in SAP Human Capital Management for SAP S/4HANA, the system returns specific messages. Due to this, an authenticated user with low privileges could guess and enumerate the content shown, beyond their authorized scope. This leads to disclosure of sensitive information causing a high impact on confidentiality, while integrity and availability are unaffected.
Problem types
CWE-204: Observable Response Discrepancy
Product status
S4HCMRXX 100
101
102
SAP_HRRXX 600
604
608