Authorization Flaw in SAP ERP HCM Payroll Data Access
CVE-2019-0325
4.2MEDIUM
Summary
An authorization bypass vulnerability in SAP ERP HCM's payroll data reporting allows users who previously had access to sensitive employee payroll information to retain that access, even after their privileges have been revoked. This vulnerability arises because necessary authorization checks are not enforced, which can lead to unauthorized disclosure of payroll data, posing a significant risk to employee privacy and data integrity.
Affected Version(s)
SAP ERP HCM (SAP_HRCES) < 3
References
CVSS V3.1
Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved