Impact
The SAP Fiori App for Intercompany Balance Reconciliation contains a flaw where required authorization checks are omitted. Because the application does not verify whether an authenticated user has the correct permissions, a user who can log in may perform actions that should be restricted. The capability to elevate privileges does not impact confidentiality or availability, but it does compromise the integrity of the application data.
Affected Systems
The issue affects the SAP Fiori App (Intercompany Balance Reconciliation) from SAP SE. The vulnerability is present in the component referenced by SAP Note 3122486, but the specific product versions are not listed in the advisory. Administrators should refer to the note and accompanying patch for the exact versions they host.
Risk and Exploitability
The CVSS score of 4.3 reflects moderate risk, while the EPSS score of less than 1% indicates that real-world exploitation is unlikely at present. The vulnerability is not in the CISA KEV catalog. Because the flaw requires an authenticated user, the attack is limited to users who already have valid credentials; no public exploit has been reported. Nevertheless, patching or restricting access remains advisable.
OpenCVE Enrichment