SAP Fiori applications using the posting library fail to properly configure security settings during the setup process, leaving them at default or inadequately defined. This vulnerability allows an attacker with low privileges to bypass access controls within the application, enabling them to potentially modify data. Confidentiality and Availability are not impacted.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Mar 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 11 Mar 2025 01:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SAP Fiori applications using the posting library fail to properly configure security settings during the setup process, leaving them at default or inadequately defined. This vulnerability allows an attacker with low privileges to bypass access controls within the application, enabling them to potentially modify data. Confidentiality and Availability are not impacted. | |
Title | Broken Access Control in SAP Fiori apps (Posting Library) | |
Weaknesses | CWE-639 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-03-11T14:13:59.512Z
Reserved: 2025-02-12T21:05:31.735Z
Link: CVE-2025-26660

Updated: 2025-03-11T14:13:56.011Z

Status : Received
Published: 2025-03-11T01:15:35.837
Modified: 2025-03-11T01:15:35.837
Link: CVE-2025-26660

No data.