First published: Tue Mar 11 2025(Updated: )
An authenticated user with low privileges can exploit a missing authorization check in an IBS module of FS-RBD, allowing unauthorized access to perform actions beyond their intended permissions. This causes a low impact on integrity with no impact on confidentiality and availability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP S/4HANA (Learning Solution) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23188 has a low severity impact on integrity due to a missing authorization check.
To fix CVE-2025-23188, ensure that appropriate authorization checks are implemented in the IBS module of FS-RBD.
CVE-2025-23188 affects SAP S/4HANA users with low privileges who can exploit the vulnerability.
CVE-2025-23188 allows authenticated users to perform actions beyond their intended permissions.
CVE-2025-23188 has no impact on data confidentiality and availability.