CVE-2025-26656
CVE-2025-26656
Título es
CVE-2025-26656
Mar, 11/03/2025 – 01:15
Tipo
CWE-862
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-26656
Descripción en
OData Service in Manage Purchasing Info Records does not perform necessary authorization checks for an authenticated user, allowing an attacker to escalate privileges. This has low impact on integrity of the application.
11/03/2025
11/03/2025
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Gravedad 3.1 (CVSS 3.1 Base Score)
4.30
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
MEDIUM
Referencias
https://me.sap.com/notes/3474392
https://url.sap/sapsecuritypatchday
Enviar en el boletín
Off
