VDB

CISA-2025-23188

CISA-2025-23188 PUBLISHED CVSS 4.3 MEDIUM

Reported by sap · Published March 11, 2025

An authenticated user with low privileges can exploit a missing authorization check in an IBS module of FS-RBD, allowing unauthorized access to perform actions beyond their intended permissions. This causes a low impact on integrity with no impact on confidentiality and availability.

Risk Scores

CVSS 3.1
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Affected Products

VendorProductVersions
SAP_SESAP S/4HANA (RBD)S4CORE 102, 103, 104
SAP_SESAP S/4HANA (RBD)S4CORE 102, 103, 104

Timeline

  • Mar 11, 2025 CVE Published
  • Mar 11, 2025 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›