PT-2017-14523 · Sap · Sap Business Intelligence Promotion Management Application
Publicado
2017-12-12
·
Atualizado
2017-12-22
·
CVE-2017-16684
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP Business Intelligence Promotion Management Application versions 4.10 through 4.30
Description
The issue concerns the lack of authentication checks for certain functionalities that require user identity.
Recommendations
For versions 4.10 through 4.30, consider implementing additional authentication checks for functionalities that require user identity as a temporary workaround until a patch is available.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sap Business Intelligence Promotion Management Application