CVE-2023-32112
Summary
| CVE | CVE-2023-32112 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-09 02:15:00 UTC |
| Updated | 2023-05-15 17:23:00 UTC |
| Description | Vendor Master Hierarchy - versions SAP_APPL 500, SAP_APPL 600, SAP_APPL 602, SAP_APPL 603, SAP_APPL 604, SAP_APPL 605, SAP_APPL 606, SAP_APPL 616, SAP_APPL 617, SAP_APPL 618, S4CORE 100, does not perform necessary authorization checks for an authenticated user to access some of its function. This could lead to modification of data impacting the integrity of the system. |
Risk And Classification
Problem Types: CWE-862
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | S4core | 100 | All | All | All |
| Application | Sap | Vendor Master Hierarchy | sap_appl_500 | All | All | All |
| Application | Sap | Vendor Master Hierarchy | sap_appl_600 | All | All | All |
| Application | Sap | Vendor Master Hierarchy | sap_appl_602 | All | All | All |
| Application | Sap | Vendor Master Hierarchy | sap_appl_603 | All | All | All |
| Application | Sap | Vendor Master Hierarchy | sap_appl_604 | All | All | All |
| Application | Sap | Vendor Master Hierarchy | sap_appl_605 | All | All | All |
| Application | Sap | Vendor Master Hierarchy | sap_appl_606 | All | All | All |
| Application | Sap | Vendor Master Hierarchy | sap_appl_616 | All | All | All |
| Application | Sap | Vendor Master Hierarchy | sap_appl_617 | All | All | All |
| Application | Sap | Vendor Master Hierarchy | sap_appl_618 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Access Denied | MISC | www.sap.com | |
| launchpad.support.sap.com | MISC | launchpad.support.sap.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.