CVE-2023-32112: Missing Authorization Check in Vendor Master Hierarchy

Published May 9, 2023
·
Updated

Vendor Master Hierarchy - versions SAPAPPL 500, SAPAPPL 600, SAPAPPL 602, SAPAPPL 603, SAPAPPL 604, SAPAPPL 605, SAPAPPL 606, SAPAPPL 616, SAPAPPL 617, SAPAPPL 618, S4CORE 100, does not perform necessary authorization checks for an authenticated user to access some of its function. This could lead to modification of data impacting the integrity of the system.

Affected Software

11 affected components
SAP S4CORE=100
SAP Vendor Master Hierarchy=sap_appl_500
SAP Vendor Master Hierarchy=sap_appl_600
SAP Vendor Master Hierarchy=sap_appl_602
SAP Vendor Master Hierarchy=sap_appl_603
SAP Vendor Master Hierarchy=sap_appl_604
SAP Vendor Master Hierarchy=sap_appl_605
SAP Vendor Master Hierarchy=sap_appl_606
SAP Vendor Master Hierarchy=sap_appl_616
SAP Vendor Master Hierarchy=sap_appl_617
SAP Vendor Master Hierarchy=sap_appl_618

Event History

May 9, 2023
CVE Published
via MITRE·01:42 AM
Data Sourced
via MITRE·01:42 AM
DescriptionSeverity
Data Sourced
02:15 AM
DescriptionWeakness

Frequently Asked Questions

1

What is vulnerability CVE-2023-32112?

Vulnerability CVE-2023-32112 is a security flaw in the Vendor Master Hierarchy software that allows authenticated users to access certain functions without proper authorization checks.

2

Which versions of SAP_APPL are affected by CVE-2023-32112?

Versions SAP_APPL 500, SAP_APPL 600, SAP_APPL 602, SAP_APPL 603, SAP_APPL 604, SAP_APPL 605, SAP_APPL 606, SAP_APPL 616, SAP_APPL 617, SAP_APPL 618, and S4CORE 100 are affected by CVE-2023-32112.

3

What is the severity of vulnerability CVE-2023-32112?

The severity of vulnerability CVE-2023-32112 is medium, with a severity value of 5.5.

4

How can I fix vulnerability CVE-2023-32112?

To fix vulnerability CVE-2023-32112, it is recommended to apply the necessary patches or updates provided by SAP.

5

Where can I find more information about vulnerability CVE-2023-32112?

More information about vulnerability CVE-2023-32112 can be found on the SAP website and in the SAP support notes.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203