CVE-2023-40625

S4CORE (Manage Purchase Contracts App) - versions 102, 103, 104, 105, 106, 107, does not perform necessary authorization checks for an authenticated user. This could allow an attacker to perform unintended actions resulting in escalation of privileges which has low impact on confidentiality and integrity with no impact on availibility of the system.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:s4core:102:*:*:*:*:*:*:*
cpe:2.3:a:sap:s4core:103:*:*:*:*:*:*:*
cpe:2.3:a:sap:s4core:104:*:*:*:*:*:*:*
cpe:2.3:a:sap:s4core:105:*:*:*:*:*:*:*
cpe:2.3:a:sap:s4core:106:*:*:*:*:*:*:*
cpe:2.3:a:sap:s4core:107:*:*:*:*:*:*:*

History

21 Nov 2024, 08:19

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-12 03:15

Updated : 2024-11-21 08:19


NVD link : CVE-2023-40625

Mitre link : CVE-2023-40625

CVE.ORG link : CVE-2023-40625


JSON object : View

Products Affected

sap

  • s4core
CWE
CWE-862

Missing Authorization