Description
In SAP GRC (Process Control) - versions GRCFND_A V1200, GRCFND_A V8100, GRCPINW V1100_700, GRCPINW V1100_731, GRCPINW V1200_750, remote-enabled function module in the proprietary SAP solution enables an authenticated attacker with minimal privileges to access all the confidential data stored in the database. Successful exploitation of this vulnerability can expose user credentials from client-specific tables of the database, leading to high impact on confidentiality.
References (2)
Core 2
Core References
Permissions Required
https://launchpad.support.sap.com/#/notes/3281724
Scores
CVSS v3
6.5
EPSS
0.0025
EPSS Percentile
47.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-862
Status
published
Products (5)
sap/grc_process_control
v1100_700
sap/grc_process_control
v1100_731
sap/grc_process_control
v1200
sap/grc_process_control
v1200_750
sap/grc_process_control
v8100
Published
Feb 14, 2023
Tracked Since
Feb 18, 2026