CVE-2021-21467 Information

Description

SAP Banking Services (Generic Market Data) does not perform necessary authorization checks for an authenticated user resulting in escalation of privileges. An unauthorized User is allowed to display restricted Business Partner Generic Market Data (GMD) due to improper authorization check.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Reference

https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=564760476 https://launchpad.support.sap.com/#/notes/3008422

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

LOW

Availability Impact

NONE

Base Score

NONE

Base Severity

4.3

Share on: