PT-2018-15560 · Sap · Sap R/3 Enterprise Retail
Publicado
2018-07-10
·
Atualizado
2019-10-03
·
CVE-2018-2436
CVSS v2.0
6.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SAP R/3 Enterprise Retail (EHP6) version not specified
Description
The issue arises from the execution of transaction WRCK in SAP R/3 Enterprise Retail (EHP6), where necessary authorization checks for an authenticated user are not performed, leading to an escalation of privileges.
Recommendations
For SAP R/3 Enterprise Retail (EHP6), consider restricting access to the transaction WRCK until a fix is available, to minimize the risk of privilege escalation.
Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sap R/3 Enterprise Retail