SAP Just In Time(JIT) does not perform necessary authorization checks for an authenticated user, allowing attacker to escalate privileges that would otherwise be restricted, potentially causing a low impact on the integrity of the application.Confidentiality and Availability are not impacted.
History

Tue, 11 Mar 2025 02:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Mar 2025 01:00:00 +0000

Type Values Removed Values Added
Description SAP Just In Time(JIT) does not perform necessary authorization checks for an authenticated user, allowing attacker to escalate privileges that would otherwise be restricted, potentially causing a low impact on the integrity of the application.Confidentiality and Availability are not impacted.
Title Missing Authorization check in SAP JIT(Outbound)
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-03-11T00:35:06.396Z

Updated: 2025-03-11T02:09:32.603Z

Reserved: 2025-02-12T21:05:31.735Z

Link: CVE-2025-26655

cve-icon Vulnrichment

Updated: 2025-03-11T02:09:29.116Z

cve-icon NVD

Status : Received

Published: 2025-03-11T01:15:35.230

Modified: 2025-03-11T01:15:35.230

Link: CVE-2025-26655

cve-icon Redhat

No data.