The eDocument Cockpit (Inbound NF-e) in SAP Electronic Invoicing for Brazil allows an authenticated attacker with certain privileges to gain unauthorized access to each transaction. By executing the specific ABAP method within the ABAP system, an unauthorized attacker could call each transaction and view the inbound delivery details. This vulnerability has a low impact on the confidentiality with no effect on the integrity and the availability of the application.
History

Tue, 11 Mar 2025 02:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Mar 2025 01:00:00 +0000

Type Values Removed Values Added
Description The eDocument Cockpit (Inbound NF-e) in SAP Electronic Invoicing for Brazil allows an authenticated attacker with certain privileges to gain unauthorized access to each transaction. By executing the specific ABAP method within the ABAP system, an unauthorized attacker could call each transaction and view the inbound delivery details. This vulnerability has a low impact on the confidentiality with no effect on the integrity and the availability of the application.
Title Missing Authorization check in SAP Electronic Invoicing for Brazil (eDocument Cockpit)
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 2.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2025-03-11T02:05:41.312Z

Reserved: 2025-02-25T09:29:51.244Z

Link: CVE-2025-27432

cve-icon Vulnrichment

Updated: 2025-03-11T02:05:36.830Z

cve-icon NVD

Status : Received

Published: 2025-03-11T01:15:36.467

Modified: 2025-03-11T01:15:36.467

Link: CVE-2025-27432

cve-icon Redhat

No data.