PT-2018-1591 · Sap · Sap Enterprise Financial Services

Publicado

2018-09-11

·

Atualizado

2019-10-03

·

CVE-2018-2455

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP Enterprise Financial Services versions 6.05 through 6.18, 8.0
Description The issue is related to errors in the authorization procedure of the EAFS BCA BUSOPR SEPA function in the SAP Enterprise Financial Services platform. This can allow a remote attacker to escalate their privileges. The problem arises because the software does not perform necessary authorization checks for an authenticated user.
Recommendations For SAP Enterprise Financial Services versions 6.05 through 6.18, 8.0, ensure that necessary authorization checks are implemented for authenticated users to prevent privilege escalation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-01148
CVE-2018-2455

Produtos afetados

Sap Enterprise Financial Services