CVE Vulnerabilities

CVE-2023-35870

Published: Jul 11, 2023 | Modified: Jul 19, 2023
CVSS 3.x
7.3
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

When creating a journal entry template in SAP S/4HANA (Manage Journal Entry Template) - versions S4CORE 104, 105, 106, 107, an attacker could intercept the save request and change the template, leading to an impact on confidentiality and integrity of the resource. Furthermore, a standard template could be deleted, hence making the resource temporarily unavailable.

Affected Software

Name Vendor Start Version End Version
S4core Sap 104 (including) 104 (including)
S4core Sap 105 (including) 105 (including)
S4core Sap 106 (including) 106 (including)
S4core Sap 107 (including) 107 (including)

References