Vulnerabilities > SAP > ERP Financials Information System > High

DATE CVE VULNERABILITY TITLE RISK
2018-02-14 CVE-2018-2381 Missing Authorization vulnerability in SAP ERP Financials Information System 2.0
SAP ERP Financials Information System (SAP_APPL 6.00, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16; SAP_FIN 6.17, 6.18, 7.00, 7.20, 7.30 S4CORE 1.00, 1.01, 1.02) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
network
low complexity
sap CWE-862
8.8