CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:L/Au:S/C:P/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
AI Score
Confidence
High
EPSS
Percentile
28.4%
SAP ERP (HCM Travel Management), versions - 600, 602, 603, 604, 605, 606, 607, 608, allows an authenticated but unauthorized attacker to read, modify and settle trips, resulting in escalation of privileges, due to Missing Authorization Check.
Vendor | Product | Version | CPE |
---|---|---|---|
sap | hcm_travel_management | 600 | cpe:2.3:a:sap:hcm_travel_management:600:*:*:*:*:*:*:* |
sap | hcm_travel_management | 602 | cpe:2.3:a:sap:hcm_travel_management:602:*:*:*:*:*:*:* |
sap | hcm_travel_management | 603 | cpe:2.3:a:sap:hcm_travel_management:603:*:*:*:*:*:*:* |
sap | hcm_travel_management | 604 | cpe:2.3:a:sap:hcm_travel_management:604:*:*:*:*:*:*:* |
sap | hcm_travel_management | 605 | cpe:2.3:a:sap:hcm_travel_management:605:*:*:*:*:*:*:* |
sap | hcm_travel_management | 606 | cpe:2.3:a:sap:hcm_travel_management:606:*:*:*:*:*:*:* |
sap | hcm_travel_management | 607 | cpe:2.3:a:sap:hcm_travel_management:607:*:*:*:*:*:*:* |
sap | hcm_travel_management | 608 | cpe:2.3:a:sap:hcm_travel_management:608:*:*:*:*:*:*:* |
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:L/Au:S/C:P/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
AI Score
Confidence
High
EPSS
Percentile
28.4%