SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identity information, unauthorized access to sensitive user data and potential disruption of normal system usage.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HSap Basis
APPSap700701702731740750751752753754755756757758804+ 3 more
Related vulnerabilities
SAP NetWeaver AS ABAP – nieautoryzowany dostęp do danych przez słabą kontrolę dostępu
SAP NetWeaver AS ABAP and ABAP Platform does not check for authorization when a user executes some RFC functio...
The (1) SAP_BASIS and (2) SAP_ABA components 7.00 SP Level 0031 in SAP NetWeaver 2004s might allow remote atta...
Debido a la falta de verificación de autorización en SAP NetWeaver Application Server ABAP y SAP S/4HANA, un a...
Błędna kontrola autoryzacji w SAP Business Workflow prowadzi do privilege escalation. Uwierzytelniony użytkown...