VYPR

Successfactors Mobile

by SAP

CVEs (2)

  • CVE-2022-35291HigJul 27, 2022
    risk 0.53cvss 8.1epss 0.01

    Due to misconfigured application endpoints, SAP SuccessFactors attachment APIs allow attackers with user privileges to perform activities with admin privileges over the network. These APIs were consumed in the SF Mobile application for Time Off, Time Sheet, EC Workflow, and…

  • CVE-2021-40498MedOct 12, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in SAP SuccessFactors Mobile Application for Android - versions older than 2108, which allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service, which can lead to denial of service.…