Impact
The SAP Fiori App for Manage Service Entry Sheets lacks sufficient authorization checks for authenticated users, allowing them to perform privileged operations. This flaw permits a non-privileged user to elevate privileges within the application. The impact on data integrity is low, and there is no effect on confidentiality or availability.
Affected Systems
Vendors affected include SAP, specifically the SAP Fiori App (Manage Service Entry Sheets – Lean Services). The vulnerability applies to SAP S/4HANA core releases 102 through 107 as listed in the CPE data.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation. The flaw is not currently listed in CISA's KEV catalog. Exploitation requires the attacker to be authenticated to the Fiori application; once logged in, the absence of proper authorization enables the user to execute privileged actions that should be restricted.
OpenCVE Enrichment