Sap Master Data Governance vulnerabilities
3 known vulnerabilities affecting sap/master_data_governance.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2020-6249P3HIGHCVSS 8.8v101v102+3 more2020-05-12
CVE-2020-6249 [HIGH] CWE-89 CVE-2020-6249: The use of an admin backend report within SAP Master Data Governance, versions - S4CORE 101, S4FND 1
The use of an admin backend report within SAP Master Data Governance, versions - S4CORE 101, S4FND 102, 103, 104, SAP_BS_FND 748; allows an attacker to execute crafted database queries, exposing the backend database, leading to SQL Injection.
nvd
CVE-2023-49058P4MEDIUMCVSS 5.3v731v732+15 more2023-12-12
CVE-2023-49058 [MEDIUM] CWE-22 CVE-2023-49058: SAP Master Data Governance File Upload application allows an attacker to exploit insufficient valida
SAP Master Data Governance File Upload application allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing ‘traverse to parent directory’ are passed through to the file APIs. As a result, it has a low impact to the confidentiality.
nvd
CVE-2020-6256P4MEDIUMCVSS 4.3v748v749+8 more2020-05-12
CVE-2020-6256 [MEDIUM] CWE-862 CVE-2020-6256: SAP Master Data Governance, versions - 748, 749, 750, 751, 752, 800, 801, 802, 803, 804, allows user
SAP Master Data Governance, versions - 748, 749, 750, 751, 752, 800, 801, 802, 803, 804, allows users to display change request details without having required authorizations, due to Missing Authorization Check.
nvd