First published: Wed Nov 10 2021(Updated: )
SAP ERP HCM Portugal does not perform necessary authorization checks for a report that reads the payroll data of employees in a certain area. Since the affected report only reads the payroll information, the attacker can neither modify any information nor cause availability impacts.
Credit: cna@sap.com cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP ERP | =600 | |
SAP ERP | =604 | |
SAP ERP | =608 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42062 has a medium severity level due to the lack of proper authorization checks in the payroll data report.
To fix CVE-2021-42062, apply the official patch provided by SAP for the affected versions of its ERP HCM Portugal software.
CVE-2021-42062 affects SAP ERP HCM versions 600, 604, and 608 specifically for the Portugal release.
No, an attacker cannot modify payroll information through CVE-2021-42062 as it only allows reading the data.
CVE-2021-42062 potentially exposes payroll data of employees in certain areas without sufficient authorization checks.