Description
An issue was discovered in SAP E-Recruiting (aka ERECRUIT) 605 through 617. When an external applicant registers to the E-Recruiting application, he/she receives a link by email to confirm access to the provided email address. However, this measure can be bypassed and attackers can register and confirm email addresses that they do not have access to (candidate_hrobject is predictable and corr_act_guid is improperly validated). Furthermore, since an email address can be registered only once, an attacker could prevent other legitimate users from registering. This is SAP Security Note 2507798.
References (3)
Core 3
Core References
Third Party Advisory x_refsource_misc
https://www.sec-consult.com/en/blog/advisories/email-verification-bypass-in-sap-e-recruiting/index.html
Vendor Advisory x_refsource_misc
https://blogs.sap.com/2017/09/12/sap-security-patch-day-september-2017/
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2507798
Scores
CVSS v3
7.5
EPSS
0.0053
EPSS Percentile
67.3%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-20
Status
published
Products (4)
sap/e-recruiting
605
sap/e-recruiting
606
sap/e-recruiting
616
sap/e-recruiting
617
Published
Sep 17, 2017
Tracked Since
Feb 18, 2026