CVE-2021-42062: Medium severity sap erp vulnerability
SAP ERP HCM Portugal does not perform necessary authorization checks for a report that reads the payroll data of employees in a certain area. Since the affected report only reads the payroll information, the attacker can neither modify any information nor cause availability impacts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-42062?
CVE-2021-42062 has a medium severity level due to the lack of proper authorization checks in the payroll data report.
How do I fix CVE-2021-42062?
To fix CVE-2021-42062, apply the official patch provided by SAP for the affected versions of its ERP HCM Portugal software.
Which versions of SAP ERP HCM are affected by CVE-2021-42062?
CVE-2021-42062 affects SAP ERP HCM versions 600, 604, and 608 specifically for the Portugal release.
Can an attacker modify payroll information through CVE-2021-42062?
No, an attacker cannot modify payroll information through CVE-2021-42062 as it only allows reading the data.
What types of data are exposed in CVE-2021-42062?
CVE-2021-42062 potentially exposes payroll data of employees in certain areas without sufficient authorization checks.