PT-2018-15560 · Sap · Sap R/3 Enterprise Retail
Published
2018-07-10
·
Updated
2019-10-03
·
CVE-2018-2436
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SAP R/3 Enterprise Retail (EHP6) version not specified
Description
The issue arises from the execution of transaction WRCK in SAP R/3 Enterprise Retail (EHP6), where necessary authorization checks for an authenticated user are not performed, leading to an escalation of privileges.
Recommendations
For SAP R/3 Enterprise Retail (EHP6), consider restricting access to the transaction WRCK until a fix is available, to minimize the risk of privilege escalation.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap R/3 Enterprise Retail