Unauthorized Access Vulnerability in SAP ERP Financial Accounting
CVE-2021-38164

5.4MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
14 September 2021

Summary

A vulnerability exists in SAP ERP Financial Accounting that permits a registered attacker to execute functions typically restricted to specific users. This flaw permits unauthorized access to sensitive financial data, which could lead to unjustified viewing and modification of accounting information that should remain confidential. The affected versions expose certain functions over the network, making it imperative for organizations to address this security gap to protect their financial integrity.

Affected Version(s)

SAP ERP Financial Accounting (RFOPENPOSTING_FR) < SAP_APPL - 600 < SAP_APPL - 600

SAP ERP Financial Accounting (RFOPENPOSTING_FR) < 602 < 602

SAP ERP Financial Accounting (RFOPENPOSTING_FR) < 603 < 603

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.