Authorization Flaw in SAP ERP HCM Payroll Data Access
CVE-2019-0325

4.2MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
10 July 2019

Summary

An authorization bypass vulnerability in SAP ERP HCM's payroll data reporting allows users who previously had access to sensitive employee payroll information to retain that access, even after their privileges have been revoked. This vulnerability arises because necessary authorization checks are not enforced, which can lead to unauthorized disclosure of payroll data, posing a significant risk to employee privacy and data integrity.

Affected Version(s)

SAP ERP HCM (SAP_HRCES) < 3

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.