2023-09-12 16:00:29 +00:00
{
"id" : "CVE-2023-40625" ,
2023-09-13 16:00:28 +00:00
"sourceIdentifier" : "cna@sap.com" ,
2023-09-12 16:00:29 +00:00
"published" : "2023-09-12T03:15:14.147" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T08:19:50.863" ,
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-09-12 16:00:29 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "S4CORE (Manage Purchase Contracts App) - versions 102, 103, 104, 105, 106, 107, does not perform necessary authorization checks for an authenticated user. This could allow an attacker to perform unintended actions resulting in escalation of privileges which has low impact on confidentiality and integrity with no impact on availibility of the system.\n\n"
2024-04-04 08:46:00 +00:00
} ,
{
"lang" : "es" ,
"value" : "S4CORE (Manage Purchase Contracts App): versiones 102, 103, 104, 105, 106, 107, no realiza las comprobaciones de autorizaci\u00f3n necesarias para un usuario autenticado. Esto podr\u00eda permitir a un atacante realizar acciones no intencionadas, lo que resulta en una escalada de privilegios que tiene un bajo impacto en la confidencialidad y la integridad sin impacto en la disponibilidad del sistema."
2023-09-12 16:00:29 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
2024-12-08 03:06:42 +00:00
"source" : "cna@sap.com" ,
"type" : "Secondary" ,
2023-09-13 16:00:28 +00:00
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 5.4 ,
"baseSeverity" : "MEDIUM" ,
2023-09-13 16:00:28 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2023-09-13 16:00:28 +00:00
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 2.5
} ,
{
2024-12-08 03:06:42 +00:00
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
2023-09-12 16:00:29 +00:00
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 5.4 ,
"baseSeverity" : "MEDIUM" ,
2023-09-12 16:00:29 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "NONE"
2023-09-12 16:00:29 +00:00
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 2.5
}
]
} ,
"weaknesses" : [
{
2023-09-13 16:00:28 +00:00
"source" : "cna@sap.com" ,
2024-12-15 03:03:56 +00:00
"type" : "Primary" ,
2023-09-12 16:00:29 +00:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-862"
}
]
}
] ,
2023-09-13 16:00:28 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sap:s4core:102:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "04C95A73-48EB-446C-A5F0-20E1D6BC1779"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sap:s4core:103:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "1C3C9003-68A6-4886-8979-9B7D01A35E40"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sap:s4core:104:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "964023CE-6EA4-42BB-93B2-DCE6B36D3F89"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sap:s4core:105:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "84B775EF-6C11-4FAB-B5E7-8F6C4C5674BE"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sap:s4core:106:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "14D17245-5B6D-4024-AFA6-8E0A70B294BF"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:sap:s4core:107:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "5DEFABE8-1797-4C7B-941C-3205AE90914B"
}
]
}
]
}
] ,
2023-09-12 16:00:29 +00:00
"references" : [
{
"url" : "https://me.sap.com/notes/3326361" ,
2023-09-13 16:00:28 +00:00
"source" : "cna@sap.com" ,
"tags" : [
"Permissions Required"
]
2023-09-12 16:00:29 +00:00
} ,
{
"url" : "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html" ,
2023-09-13 16:00:28 +00:00
"source" : "cna@sap.com" ,
"tags" : [
"Vendor Advisory"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://me.sap.com/notes/3326361" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Permissions Required"
]
} ,
{
"url" : "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
2023-09-12 16:00:29 +00:00
}
]
}