Skip links
Arpine Maghakyan

Arpine Maghakyan

Security Researcher of RedRays.

Missing Authorization check in EWM for delivery / warehouse request objects, SAP security note 2316942

Description

A user can change delivery/warehouse request objects even if he has no change authorization. 

Available fix and Supported packages

  • SCMEWM | 940 | 940
  • SCMEWM 940 | SAPK-94001INSCMEWM |

Affected component

    SCM-EWM-DLP
    Delivery Processing

CVSS

Score: 0

Exploit

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/2316942

TAGS

#Access-control
#Authorization-error
#Authorization-profile
#/SCDL/AF061
#/SCDL/AF-061

More to explorer

SAP Cloud Connector Certificate Validation Issue

Date of Release: February 13, 2024 Advisory ID: CVE-2024-25642 Affected Software: SAP Cloud Connector Versions Affected: 2.15.0 to 2.16.1 Vulnerability Summary:A critical vulnerability,