Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Missing Authorization check in SAP S/4 HANA (Cash Management)
Vulnerability Description
Cash Management in SAP S/4 HANA does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. By exploiting this vulnerability, an attacker can approve or reject a bank account application affecting the integrity of the application. Confidentiality and Availability are not impacted.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
SAP S/4 HANA 安全漏洞
Vulnerability Description
SAP S/4 HANA是德国思爱普(SAP)公司的一款适用于大型企业的智能化集成式ERP软件。 SAP S/4 HANA存在安全漏洞,该漏洞源于不会对经过身份验证的用户执行必要的授权检查,从而导致权限升级。
CVSS Information
N/A
Vulnerability Type
N/A