PT-2019-4585 · Sap · Sap Erp Hcm
Published
2019-07-09
·
Updated
2020-08-24
·
CVE-2019-0325
CVSS v2.0
4.9
Medium
| Vector | AV:N/AC:M/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
SAP ERP HCM (SAP HRCES) version 3
Description
The issue arises from insufficient authorization checks in a report that reads payroll data of employees in a certain area. This can lead to a situation where a user who once had authorization to payroll data, but later had it revoked, may still retain access to the same data. The vulnerability is caused by weaknesses in the authorization procedure, which can be exploited by a remote attacker to elevate their privileges.
Recommendations
For SAP ERP HCM (SAP HRCES) version 3, consider implementing additional authorization checks for the report that reads payroll data to prevent unauthorized access. As a temporary workaround, restrict access to the payroll data report until a proper fix is applied.
Fix
Improper Authorization
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap Erp Hcm