SAP Financial Consolidation - version 10.1, does not perform necessary authorization checks for updating homepage messages, resulting for an unauthorized user to alter the maintenance system message.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://dam.sap.com/mac/embed/public/pdf/a/ucQrx6G.htm?rc=10 | vendor advisory |
https://launchpad.support.sap.com/#/notes/3144941 | permissions required vendor advisory |