PT-2018-15560 · Sap · Sap R/3 Enterprise Retail

Published

2018-07-10

·

Updated

2019-10-03

·

CVE-2018-2436

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SAP R/3 Enterprise Retail (EHP6) version not specified
Description The issue arises from the execution of transaction WRCK in SAP R/3 Enterprise Retail (EHP6), where necessary authorization checks for an authenticated user are not performed, leading to an escalation of privileges.
Recommendations For SAP R/3 Enterprise Retail (EHP6), consider restricting access to the transaction WRCK until a fix is available, to minimize the risk of privilege escalation.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-2436

Affected Products

Sap R/3 Enterprise Retail