Home
MEDIUM: 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NDefault status
unaffected
SAP_APPL 618
affected
S4CORE 102
affected
103
affected
104
affected
105
affected
106
affected
107
affected
108
affected
109
affected
EA-APPL 600
affected
604
affected
605
affected
606
affected
617
affected
Description
Due to insufficient authorization checks in the SAP Incentive and Commission Management application, authenticated users could invoke a remote-enabled function module to perform table update operations. This vulnerability has a low impact on integrity with no impact on confidentiality and availability of the application.
Problem types
CWE-862: Missing Authorization
Product status
SAP_APPL 618
S4CORE 102
103
104
105
106
107
108
109
EA-APPL 600
604
605
606
617