SAP Service Parts Management Privilege Escalation Vulnerability
Vulnerability
A privilege escalation vulnerability has been identified in SAP Service Parts Management (SPM). The issue arises because the application fails to implement necessary authorization checks for authenticated users, allowing attackers to escalate privileges. This vulnerability has a low impact on the application's confidentiality, integrity, and availability.
Impact
Exploitation of this vulnerability allows for unauthorized privilege escalation within the application.
Remediation
Users are advised to review and implement the SAP Security Notes available in SAP for Me. Security fixes for SAP NetWeaver-based products are delivered with support packages. For details on the SAP Security Patch Day schedule and how to access SAP Security Notes, refer to the SAP Security Notes FAQ.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
