CVE-2023-32112: Missing Authorization Check in Vendor Master Hierarchy
Vendor Master Hierarchy - versions SAPAPPL 500, SAPAPPL 600, SAPAPPL 602, SAPAPPL 603, SAPAPPL 604, SAPAPPL 605, SAPAPPL 606, SAPAPPL 616, SAPAPPL 617, SAPAPPL 618, S4CORE 100, does not perform necessary authorization checks for an authenticated user to access some of its function. This could lead to modification of data impacting the integrity of the system.
Affected Software
Event History
Frequently Asked Questions
What is vulnerability CVE-2023-32112?
Vulnerability CVE-2023-32112 is a security flaw in the Vendor Master Hierarchy software that allows authenticated users to access certain functions without proper authorization checks.
Which versions of SAP_APPL are affected by CVE-2023-32112?
Versions SAP_APPL 500, SAP_APPL 600, SAP_APPL 602, SAP_APPL 603, SAP_APPL 604, SAP_APPL 605, SAP_APPL 606, SAP_APPL 616, SAP_APPL 617, SAP_APPL 618, and S4CORE 100 are affected by CVE-2023-32112.
What is the severity of vulnerability CVE-2023-32112?
The severity of vulnerability CVE-2023-32112 is medium, with a severity value of 5.5.
How can I fix vulnerability CVE-2023-32112?
To fix vulnerability CVE-2023-32112, it is recommended to apply the necessary patches or updates provided by SAP.
Where can I find more information about vulnerability CVE-2023-32112?
More information about vulnerability CVE-2023-32112 can be found on the SAP website and in the SAP support notes.