Description
Due to insufficient input validation, SAP Employee Self Service allows an authenticated attacker with user privileges to alter employee number. On successful exploitation, the attacker can view personal details of other users causing a limited impact on confidentiality of the application.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-33944 | Due to insufficient input validation, SAP Employee Self Service allows an authenticated attacker with user privileges to alter employee number. On successful exploitation, the attacker can view personal details of other users causing a limited impact on confidentiality of the application. |
References
History
No history.
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-08-03T06:26:06.562Z
Reserved: 2022-04-25T00:00:00.000Z
Link: CVE-2022-29613
No data.
Status : Modified
Published: 2022-05-11T15:15:09.940
Modified: 2024-11-21T06:59:25.970
Link: CVE-2022-29613
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD