PT-2021-23496 · Sap · Sap Erp Hcm Portugal

Published

2021-11-10

·

Updated

2021-11-15

·

CVE-2021-42062

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP ERP HCM Portugal (affected versions not specified)
Description The issue is related to a report that reads payroll data of employees in a certain area, where necessary authorization checks are not performed. This allows an attacker to read payroll information, but they cannot modify any information or cause availability impacts.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-42062

Affected Products

Sap Erp Hcm Portugal