SAP CRM WebClient does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to access some sensitive information.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://url.sap/sapsecuritypatchday | vendor advisory |
https://me.sap.com/notes/3467377 | permissions required |