CVE-2021-40502 Information

Description

SAP Commerce - versions 2105.3 2011.13 2005.18 1905.34 does not perform necessary authorization checks for an authenticated user resulting in escalation of privileges. Authenticated attackers will be able to access and edit data from b2b units they do not belong to.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Reference

https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=589496864 https://launchpad.support.sap.com/#/notes/3110328

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

8.8

Share on: