| Title | SAP Enterprise Financial Services における認可・権限・アクセス制御に関する脆弱性 |
|---|---|
| Summary | SAP Enterprise Financial Services には、認可・権限・アクセス制御に関する脆弱性が存在します。 |
| Possible impacts | 情報を取得される、および情報を改ざんされる可能性があります。 |
| Solution | ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date | May 8, 2018, midnight |
| Registration Date | July 4, 2018, 4:23 p.m. |
| Last Update | July 4, 2018, 4:23 p.m. |
| CVSS3.0 : 警告 | |
| Score | 4.6 |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N |
| CVSS2.0 : 警告 | |
| Score | 5.5 |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
| SAP |
| EA-FINSERV 6.04 |
| EA-FINSERV 6.05 |
| EA-FINSERV 6.06 |
| EA-FINSERV 6.16 |
| EA-FINSERV 6.17 |
| EA-FINSERV 6.18 |
| EA-FINSERV 8.0 |
| S4CORE 1.01 |
| S4CORE 1.02 |
| SAPSCORE 1.11 |
| SAPSCORE 1.12 |
| No | Changed Details | Date of change |
|---|---|---|
| 1 | [2018年07月04日] 掲載 | July 4, 2018, 1:39 p.m. |
| Summary | SAP Enterprise Financial Services (SAPSCORE 1.11, 1.12; S4CORE 1.01, 1.02; EA-FINSERV 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. |
|---|---|
| Publication Date | May 10, 2018, 5:29 a.m. |
| Registration Date | March 1, 2021, 7:21 p.m. |
| Last Update | Nov. 21, 2024, 1:03 p.m. |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:a:sap:sapscore:1.12:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:sap:sapscore:1.11:*:*:*:*:*:*:* | |||||
| Configuration2 | or higher | or less | more than | less than | |
| cpe:2.3:a:sap:s4core:1.02:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:sap:s4core:1.01:*:*:*:*:*:*:* | |||||
| Configuration3 | or higher | or less | more than | less than | |
| cpe:2.3:a:sap:ea-finserv:6.04:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:sap:ea-finserv:6.05:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:sap:ea-finserv:6.06:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:sap:ea-finserv:6.16:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:sap:ea-finserv:6.17:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:sap:ea-finserv:6.18:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:sap:ea-finserv:8.0:*:*:*:*:*:*:* | |||||