Under certain conditions SAP Permit to Work allows an authenticated attacker to access information which would otherwise be restricted causing low impact on the confidentiality of the application.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://me.sap.com/notes/3475427 | permissions required |
https://url.sap/sapsecuritypatchday | vendor advisory |