Impact
The vulnerability is caused by a missing authorization check in the SAP S/4HANA Condition Maintenance module. An authenticated attacker who has valid user credentials can view and modify condition table records without being granted the appropriate permissions. The impact on data confidentiality and integrity is low, but the attacker can still alter business logic and potentially disrupt processes. Additionally, legitimate users may experience minor availability loss if the manipulated records impede normal operations.
Affected Systems
The affected system is SAP S/4HANA Condition Maintenance. No specific version details are provided; the issue applies to all deployments of this product.
Risk and Exploitability
The CVSS score of 6.3 indicates medium severity. Exploitation requires authenticated access, so it may be less attractive to attackers who do not already hold valid credentials. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation. Nonetheless, authenticated users with sufficient privileges can cause unauthorized data manipulation and minor availability impacts.
OpenCVE Enrichment