Due to a missing authorization check in the Disconnected Operations of the SAP S/4HANA Defense & Security, an attacker with user privileges could call remote-enabled function modules to do direct update on standard SAP database table . This results in low impact on integrity, with no impact on confidentiality or availability of the application.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| S/4hana_defense_&_security | Sap | 600 (including) | 600 (including) |
| S/4hana_defense_&_security | Sap | 603 (including) | 603 (including) |
| S/4hana_defense_&_security | Sap | 604 (including) | 604 (including) |
| S/4hana_defense_&_security | Sap | 605 (including) | 605 (including) |
| S/4hana_defense_&_security | Sap | 606 (including) | 606 (including) |
| S/4hana_defense_&_security | Sap | 616 (including) | 616 (including) |
| S/4hana_defense_&_security | Sap | 617 (including) | 617 (including) |
| S/4hana_defense_&_security | Sap | 618 (including) | 618 (including) |
| S/4hana_defense_&_security | Sap | 619 (including) | 619 (including) |
| S/4hana_defense_&_security | Sap | 800 (including) | 800 (including) |
| S/4hana_defense_&_security | Sap | 801 (including) | 801 (including) |
| S/4hana_defense_&_security | Sap | 802 (including) | 802 (including) |
| S/4hana_defense_&_security | Sap | 803 (including) | 803 (including) |
| S/4hana_defense_&_security | Sap | 804 (including) | 804 (including) |
| S/4hana_defense_&_security | Sap | 805 (including) | 805 (including) |
| S/4hana_defense_&_security | Sap | 806 (including) | 806 (including) |
| S/4hana_defense_&_security | Sap | 807 (including) | 807 (including) |
| S/4hana_defense_&_security | Sap | 808 (including) | 808 (including) |
| S/4hana_defense_&_security | Sap | 809 (including) | 809 (including) |