Description
SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has high impact on confidentiality and integrity of the application ,availability is not impacted.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected products
- SAP_SE / SAP Fiori App (Intercompany Balance Reconciliation)UIAPFI70 500 – UIAPFI70 500
- SAP_SE / SAP Fiori App (Intercompany Balance Reconciliation)600 – 600
- SAP_SE / SAP Fiori App (Intercompany Balance Reconciliation)700 – 700
- SAP_SE / SAP Fiori App (Intercompany Balance Reconciliation)800 – 800
- SAP_SE / SAP Fiori App (Intercompany Balance Reconciliation)900 – 900
- SAP_SE / SAP Fiori App (Intercompany Balance Reconciliation)901 – 901
- SAP_SE / SAP Fiori App (Intercompany Balance Reconciliation)902 – 902
- SAP_SE / SAP Fiori App (Intercompany Balance Reconciliation)S4CORE 102 – S4CORE 102
- SAP_SE / SAP Fiori App (Intercompany Balance Reconciliation)103 – 103
- SAP_SE / SAP Fiori App (Intercompany Balance Reconciliation)104 – 104
- SAP_SE / SAP Fiori App (Intercompany Balance Reconciliation)105 – 105
- SAP_SE / SAP Fiori App (Intercompany Balance Reconciliation)106 – 106
- SAP_SE / SAP Fiori App (Intercompany Balance Reconciliation)107 – 107
- SAP_SE / SAP Fiori App (Intercompany Balance Reconciliation)108 – 108