Authorization Flaw in SAP ERP HCM Payroll Data Access
CVE-2019-0325
4.2MEDIUM
What is CVE-2019-0325?
An authorization bypass vulnerability in SAP ERP HCM's payroll data reporting allows users who previously had access to sensitive employee payroll information to retain that access, even after their privileges have been revoked. This vulnerability arises because necessary authorization checks are not enforced, which can lead to unauthorized disclosure of payroll data, posing a significant risk to employee privacy and data integrity.
Affected Version(s)
SAP ERP HCM (SAP_HRCES) < 3