Vulnerability Description
SAP ERP HCM Portugal does not perform necessary authorization checks for a report that reads the payroll data of employees in a certain area. Since the affected report only reads the payroll information, the attacker can neither modify any information nor cause availability impacts.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Erp Human Capital Management | 600 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/3104456Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=589496864Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3104456Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=589496864Vendor Advisory
FAQ
What is CVE-2021-42062?
CVE-2021-42062 is a vulnerability with a CVSS score of 4.3 (MEDIUM). SAP ERP HCM Portugal does not perform necessary authorization checks for a report that reads the payroll data of employees in a certain area. Since the affected report only reads the payroll informati...
How severe is CVE-2021-42062?
CVE-2021-42062 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-42062?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Erp Human Capital Management.