Vulnerabilities > CVE-2023-41368 - Authorization Bypass Through User-Controlled Key vulnerability in SAP S/4 Hana
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
LOW Availability impact
NONE Summary
The OData service of the S4 HANA (Manage checkbook apps) - versions 102, 103, 104, 105, 106, 107, allows an attacker to change the checkbook name by simulating an update OData call.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 6 |