CVE-2021-38164
Summary
| CVE | CVE-2021-38164 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-14 12:15:00 UTC |
| Updated | 2021-09-24 15:54:00 UTC |
| Description | SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, 618, 700, 720, 730, SAPSCORE - 125, S4CORE, 100, 101, 102, 103, 104, 105, allows a registered attacker to invoke certain functions that would otherwise be restricted to specific users. These functions are normally exposed over the network and once exploited the attacker may be able to view and modify financial accounting data that only a specific user should have access to. |
Risk And Classification
Problem Types: CWE-862
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Erp Financial Accounting | 100 | All | All | All |
| Application | Sap | Erp Financial Accounting | 101 | All | All | All |
| Application | Sap | Erp Financial Accounting | 102 | All | All | All |
| Application | Sap | Erp Financial Accounting | 103 | All | All | All |
| Application | Sap | Erp Financial Accounting | 104 | All | All | All |
| Application | Sap | Erp Financial Accounting | 105 | All | All | All |
| Application | Sap | Erp Financial Accounting | 602 | All | All | All |
| Application | Sap | Erp Financial Accounting | 603 | All | All | All |
| Application | Sap | Erp Financial Accounting | 604 | All | All | All |
| Application | Sap | Erp Financial Accounting | 605 | All | All | All |
| Application | Sap | Erp Financial Accounting | 606 | All | All | All |
| Application | Sap | Erp Financial Accounting | 616 | All | All | All |
| Application | Sap | Erp Financial Accounting | 618 | All | All | All |
| Application | Sap | Erp Financial Accounting | 700 | All | All | All |
| Application | Sap | Erp Financial Accounting | 720 | All | All | All |
| Application | Sap | Erp Financial Accounting | 730 | All | All | All |
| Application | Sap | Erp Financial Accounting | s4core | All | All | All |
| Application | Sap | Erp Financial Accounting | sapscore_-_125 | All | All | All |
| Application | Sap | Erp Financial Accounting | sap_appl_-_600 | All | All | All |
| Application | Sap | Erp Financial Accounting | sap_fin_-_617 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| launchpad.support.sap.com | MISC | launchpad.support.sap.com | |
| SAP Security Patch Day – September 2021 - Product Security Response at SAP - Community Wiki | MISC | wiki.scn.sap.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.