CVE-2021-40501 Information
Jun 07, 2022
cve
Description
SAP ABAP Platform Kernel - versions 7.77 7.81 7.85 7.86 does not perform necessary authorization checks for an authenticated business user resulting in escalation of privileges. That means this business user is able to read and modify data beyond the vulnerable system. However the attacker can neither significantly reduce the performance of the system nor stop the system.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Reference
https://launchpad.support.sap.com/#/notes/3099776 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=589496864
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
NONE
Base Severity
8.1
Share on: