Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could lead to information gathering for further exploits and attacks.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://dam.sap.com/mac/embed/public/pdf/a/ucQrx6G.htm?rc=10 | not applicable vendor advisory |
https://launchpad.support.sap.com/#/notes/3165856 | permissions required vendor advisory |
https://sapbasisworld.com/sap-security-notes-summary-march-2022/ | third party advisory |