Due to insufficient input validation, SAP Employee Self Service allows an authenticated attacker with user privileges to alter employee number. On successful exploitation, the attacker can view personal details of other users causing a limited impact on confidentiality of the application.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: sap
Published: 2022-05-11T14:57:56
Updated: 2024-08-03T06:26:06.562Z
Reserved: 2022-04-25T00:00:00
Link: CVE-2022-29613
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-05-11T15:15:09.940
Modified: 2024-11-21T06:59:25.970
Link: CVE-2022-29613
Redhat
No data.