CWE
862
Advisory Published
Updated

CVE-2023-32112: Missing Authorization Check in Vendor Master Hierarchy

First published: Tue May 09 2023(Updated: )

Vendor Master Hierarchy - versions SAP_APPL 500, SAP_APPL 600, SAP_APPL 602, SAP_APPL 603, SAP_APPL 604, SAP_APPL 605, SAP_APPL 606, SAP_APPL 616, SAP_APPL 617, SAP_APPL 618, S4CORE 100, does not perform necessary authorization checks for an authenticated user to access some of its function. This could lead to modification of data impacting the integrity of the system.

Credit: cna@sap.com

Affected SoftwareAffected VersionHow to fix
SAP S/4HANA=100
Sap Vendor Master Hierarchy=sap_appl_500
Sap Vendor Master Hierarchy=sap_appl_600
Sap Vendor Master Hierarchy=sap_appl_602
Sap Vendor Master Hierarchy=sap_appl_603
Sap Vendor Master Hierarchy=sap_appl_604
Sap Vendor Master Hierarchy=sap_appl_605
Sap Vendor Master Hierarchy=sap_appl_606
Sap Vendor Master Hierarchy=sap_appl_616
Sap Vendor Master Hierarchy=sap_appl_617
Sap Vendor Master Hierarchy=sap_appl_618

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is vulnerability CVE-2023-32112?

    Vulnerability CVE-2023-32112 is a security flaw in the Vendor Master Hierarchy software that allows authenticated users to access certain functions without proper authorization checks.

  • Which versions of SAP_APPL are affected by CVE-2023-32112?

    Versions SAP_APPL 500, SAP_APPL 600, SAP_APPL 602, SAP_APPL 603, SAP_APPL 604, SAP_APPL 605, SAP_APPL 606, SAP_APPL 616, SAP_APPL 617, SAP_APPL 618, and S4CORE 100 are affected by CVE-2023-32112.

  • What is the severity of vulnerability CVE-2023-32112?

    The severity of vulnerability CVE-2023-32112 is medium, with a severity value of 5.5.

  • How can I fix vulnerability CVE-2023-32112?

    To fix vulnerability CVE-2023-32112, it is recommended to apply the necessary patches or updates provided by SAP.

  • Where can I find more information about vulnerability CVE-2023-32112?

    More information about vulnerability CVE-2023-32112 can be found on the SAP website and in the SAP support notes.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203