VYPR

Access Control

by SAP

CVEs (2)

  • CVE-2021-44233HigDec 14, 2021
    risk 0.57cvss 8.8epss 0.01

    SAP GRC Access Control - versions V1100_700, V1100_731, V1200_750, does not perform necessary authorization checks for an authenticated user, which could lead to escalation of privileges.

  • CVE-2022-39801HigSep 13, 2022
    risk 0.49cvss 7.5epss 0.01

    SAP GRC Access control Emergency Access Management allows an authenticated attacker to access a Firefighter session even after it is closed in Firefighter Logon Pad. This attack can be launched only within the firewall. On successful exploitation the attacker can gain access to…