CVE-2013-3061
The ISHMED-PATRED_TRANSACT_RFCCALL function in the IS-H Industry-Specific Component Hospital subsystem in SAP Healthcare Industry Solution, and the SAP ERP central component (aka ECC 6), allows remote authenticated users to bypass intended transaction…
Does this matter?
Lower severity and a low EPSS score (1.62%). Track it; it rarely justifies an emergency change on its own.
Description
The ISHMED-PATRED_TRANSACT_RFCCALL function in the IS-H Industry-Specific Component Hospital subsystem in SAP Healthcare Industry Solution, and the SAP ERP central component (aka ECC 6), allows remote authenticated users to bypass intended transaction restrictions via unspecified vectors.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.62% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- sap/erp central component · sap/healthcare industry solution
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2013-04/0176.htmlBroken Link
- http://scn.sap.com/docs/DOC-8218Broken Link
- http://www.esnc.de/sap-security-audit-and-scan-services/security-advisories/36-privilege-escalation-in-sap-is-healthcareBroken Link
- https://service.sap.com/sap/support/notes/1691744Permissions Required
- http://archives.neohapsis.com/archives/bugtraq/2013-04/0176.htmlBroken Link
- http://scn.sap.com/docs/DOC-8218Broken Link
- http://www.esnc.de/sap-security-audit-and-scan-services/security-advisories/36-privilege-escalation-in-sap-is-healthcareBroken Link
- https://service.sap.com/sap/support/notes/1691744Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.