Missing Authorization check in SAP BW/4HANA Transformation and DTP
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.5epss 0.3%
exploitation probability
0.3%top 80% of all CVEs
observed exploitation
nono source reports it
SAP BW/4HANA Transformation and Data Transfer
Process (DTP) allows an authenticated attacker to gain higher access levels
than they should have by exploiting improper authorization checks. This results
in escalation of privileges. It has no impact on the confidentiality of data
but may have low impacts on the integrity and availability of the application.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L
Affected products
SAP_SE · SAP BW/4HANA Transformation and Data Transfer Process