CVE-2021-27609

SAP Focused RUN versions 200, 300, does not perform necessary authorization checks for an authenticated user, which allows a user to call the oData service and manipulate the activation for the SAP EarlyWatch Alert service data collection and sending to SAP without the intended authorization.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:focused_run:200:*:*:*:*:*:*:*
cpe:2.3:a:sap:focused_run:300:*:*:*:*:*:*:*

Information

Published : 2021-04-13 12:15

Updated : 2021-04-20 12:38


NVD link : CVE-2021-27609

Mitre link : CVE-2021-27609


JSON object : View

CWE
CWE-862

Missing Authorization

Advertisement

dedicated server usa

Products Affected

sap

  • focused_run