First published: Wed Aug 12 2020(Updated: )
SAP S/4 HANA (Fiori UI for General Ledger Accounting), versions 103, 104, does not perform necessary authorization checks for an authenticated user working with attachment service, allowing the attacker to delete attachments due to Missing Authorization Check.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap S\/4 Hana Fiori Ui For General Ledger Accounting | =103 | |
Sap S\/4 Hana Fiori Ui For General Ledger Accounting | =104 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.