Sap Se Sap Enterprise Financial Services vulnerabilities

4 known vulnerabilities affecting sap_se/sap_enterprise_financial_services.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2021-21486HIGHCVSS 8.8fixed in 101fixed in 102+12 more2021-03-09
CVE-2021-21486 [HIGH] CWE-862 CVE-2021-21486: SAP Enterprise Financial Services versions, 101, 102, 103, 104, 105, 600, 603, 604, 605, 606, 616, 6 SAP Enterprise Financial Services versions, 101, 102, 103, 104, 105, 600, 603, 604, 605, 606, 616, 617, 618, 800, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
cvelistv5nvd
CVE-2019-0280HIGHCVSS 8.8fixed in 1.01fixed in 1.02+1 more2019-05-14
CVE-2019-0280 [HIGH] CWE-862 CVE-2019-0280: SAP Treasury and Risk Management (EA-FINSERV 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18 and 8.0; SAP Treasury and Risk Management (EA-FINSERV 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18 and 8.0; S4CORE 1.01, 1.02 and 1.03), does not perform necessary authorization checks for authorization objects T_DEAL_DP and T_DEAL_PD , resulting in escalation of privileges.
cvelistv5nvd
CVE-2018-2484HIGHCVSS 8.8fixed in 1.13fixed in 1.14+17 more2019-01-08
CVE-2018-2484 [HIGH] CWE-862 CVE-2018-2484: SAP Enterprise Financial Services (fixed in SAPSCORE 1.13, 1.14, 1.15; S4CORE 1.01, 1.02, 1.03; EA-F SAP Enterprise Financial Services (fixed in SAPSCORE 1.13, 1.14, 1.15; S4CORE 1.01, 1.02, 1.03; EA-FINSERV 1.10, 2.0, 5.0, 6.0, 6.03, 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0; Bank/CFM 4.63_20) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
cvelistv5nvd
CVE-2018-2419MEDIUMCVSS 4.6v1.11v1.12+9 more2018-05-09
CVE-2018-2419 [MEDIUM] CWE-862 CVE-2018-2419: SAP Enterprise Financial Services (SAPSCORE 1.11, 1.12; S4CORE 1.01, 1.02; EA-FINSERV 6.04, 6.05, 6. SAP Enterprise Financial Services (SAPSCORE 1.11, 1.12; S4CORE 1.01, 1.02; EA-FINSERV 6.04, 6.05, 6.06, 6.16, 6.17, 6.18, 8.0) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
cvelistv5nvd