Missing authorization check in SAP HCM Fiori "People Profile" (GBX01 HR version 6.0) for an authenticated user which may result in an escalation of privileges.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://launchpad.support.sap.com/#/notes/2673959 | permissions required vendor advisory |
http://www.securityfocus.com/bid/105327 | vdb entry third party advisory |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499356993 | vendor advisory |