CVE-2021-27605

MEDIUM

SAP HCM Travel Management Fiori Apps V2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

SAP's HCM Travel Management Fiori Apps V2, version - 608, does not perform proper authorization check, allowing an authenticated but unauthorized attacker to read personnel numbers of employees, resulting in escalation of privileges. However, the attacker can only read some information like last name, first name of the employees, so there is some loss of confidential information, Integrity and Availability are not impacted.

References (2)

Core 2
Core References
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/3025054

Scores

CVSS v3 4.3
EPSS 0.0012
EPSS Percentile 30.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-862
Status published
Products (1)
sap/fiori_apps_2.0_for_travel_management_in_sap_erp < 608
Published Apr 13, 2021
Tracked Since Feb 18, 2026