OData Service in Manage Purchasing Info Records does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on integrity of the application.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Mar 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 11 Mar 2025 01:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | OData Service in Manage Purchasing Info Records does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on integrity of the application. | |
Title | Missing Authorization check in S/4HANA (Manage Purchasing Info Records) | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-03-11T15:12:29.986Z
Reserved: 2025-02-12T21:05:31.735Z
Link: CVE-2025-26656

Updated: 2025-03-11T15:12:23.289Z

Status : Received
Published: 2025-03-11T01:15:35.383
Modified: 2025-03-11T01:15:35.383
Link: CVE-2025-26656

No data.