Vulnerabilities > CVE-2023-41368 - Authorization Bypass Through User-Controlled Key vulnerability in SAP S/4 Hana

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
low complexity
sap
CWE-639

Summary

The OData service of the S4 HANA (Manage checkbook apps) - versions 102, 103, 104, 105, 106, 107, allows an attacker to change the checkbook name by simulating an update OData call.

Vulnerable Configurations

Part Description Count
Application
Sap
6