漏洞标题
SAP JIT(Outbound)缺失授权检查
漏洞描述信息
SAP Just In Time(JIT)未对已认证用户执行必要的授权检查,允许攻击者提升本应受到限制的权限,可能对应用的完整性造成低影响。保密性和可用性不受影响。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
漏洞类别
授权机制缺失
漏洞标题
Missing Authorization check in SAP JIT(Outbound)
漏洞描述信息
SAP Just In Time(JIT) does not perform necessary authorization checks for an authenticated user, allowing attacker to escalate privileges that would otherwise be restricted, potentially causing a low impact on the integrity of the application.Confidentiality and Availability are not impacted.
CVSS信息
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
漏洞类别
授权机制缺失