Home
MEDIUM: 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NDefault status
unaffected
S4CORE 108
affected
SAP_BASIS 916
affected
SAP_BASIS 917
affected
SAP_ABA 816
affected
Description
SAP MDG (Review Match Groups Application) does not perform the necessary authorization checks for authenticated users. This could allow a low-privileged user to perform actions that would otherwise be restricted, resulting in escalation of privileges. This has a low impact on integrity, while confidentiality and availability are not impacted.
Problem types
CWE-862: Missing Authorization
Product status
S4CORE 108
SAP_BASIS 916
SAP_BASIS 917
SAP_ABA 816