SAP ERP Financial Accounting (RFOPENPOSTING_FR) versions - SAP_APPL - 600, 602, 603, 604, 605, 606, 616, SAP_FIN - 617, 618, 700, 720, 730, SAPSCORE - 125, S4CORE, 100, 101, 102, 103, 104, 105, allows a registered attacker to invoke certain functions that would otherwise be restricted to specific users. These functions are normally exposed over the network and once exploited the attacker may be able to view and modify financial accounting data that only a specific user should have access to.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/3068582 | Permissions Required |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: sap
Published: 2021-09-14T11:19:00
Updated: 2021-09-14T11:19:00
Reserved: 2021-08-07T00:00:00
Link: CVE-2021-38164
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-09-14T12:15:10.963
Modified: 2021-09-24T15:54:03.783
Link: CVE-2021-38164
JSON object: View
Redhat Information
No data.
CWE