cbcvebase.
CVE-2021-27609
published 2021-04-13

CVE-2021-27609: SAP Focused RUN versions 200, 300, does not perform necessary authorization checks for an authenticated user, which allows a user to call the oData service and…

medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
SAP Focused RUN versions 200, 300, does not perform necessary authorization checks for an authenticated user, which allows a user to call the oData service and manipulate the activation for the SAP EarlyWatch Alert service data collection and sending to SAP without the intended authorization.

Affected

4 ranges
VendorProductVersion rangeFixed in
sapfocused_run
sapfocused_run
sap_sesap_focused_run< 200200
sap_sesap_focused_run< 300300