漏洞标题
SAP S/4HANA (RBD)缺失授权检查
漏洞描述信息
经身份验证且权限较低的用户可以利用FS-RBD组件中IBS模块缺少的授权检查,未经授权访问执行超出其预期权限的操作。这将对完整性造成低影响,对保密性和可用性无影响。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
漏洞类别
授权机制缺失
漏洞标题
Missing Authorization check in SAP S/4HANA (RBD)
漏洞描述信息
An authenticated user with low privileges can exploit a missing authorization check in an IBS module of FS-RBD, allowing unauthorized access to perform actions beyond their intended permissions. This causes a low impact on integrity with no impact on confidentiality and availability.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
漏洞类别
授权机制缺失