CVE-2015-8753
CRITICALSAP Afaria 7.0.6001.5 - Authorization Bypass via Insecure Signature
Title source: llmDescription
SAP Afaria 7.0.6001.5 allows remote attackers to bypass authorization checks and wipe or lock mobile devices via a crafted request, related to "Insecure signature," aka SAP Security Note 2134905.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_misc
https://erpscan.io/advisories/erpscan-15-023-sap-afaria-authorization-bypass-insecure-signature/
Scores
CVSS v3
9.1
EPSS
0.0047
EPSS Percentile
64.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Details
CWE
CWE-264
Status
published
Products (1)
sap/afaria
7.0.6001.5
Published
Jan 08, 2016
Tracked Since
Feb 18, 2026