SAP S/4HANA
cpe:2.3:a:sap:s/4_hana:*:*:*:*:*:*:*, +2 more
A vulnerability exists in the SAP S/4HANA backend OData Service for managing reference structures, where missing authorization checks allow an attacker to update and delete child entities through exposed OData services without proper authorization. This issue significantly impacts data integrity.
Exploitation of this vulnerability allows for unauthorized updates and deletions of child entities via the affected OData service, leading to potential integrity violations in the data management process.
Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform, specifically on the SAP Security Patch Day.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.