Unauthorized Access Vulnerability in SAP ERP Financial Accounting
CVE-2021-38164
5.4MEDIUM
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 14 September 2021
Summary
A vulnerability exists in SAP ERP Financial Accounting that permits a registered attacker to execute functions typically restricted to specific users. This flaw permits unauthorized access to sensitive financial data, which could lead to unjustified viewing and modification of accounting information that should remain confidential. The affected versions expose certain functions over the network, making it imperative for organizations to address this security gap to protect their financial integrity.
Affected Version(s)
SAP ERP Financial Accounting (RFOPENPOSTING_FR) < SAP_APPL - 600 < SAP_APPL - 600
SAP ERP Financial Accounting (RFOPENPOSTING_FR) < 602 < 602
SAP ERP Financial Accounting (RFOPENPOSTING_FR) < 603 < 603
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved