SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-3061

The ISHMED-PATRED_TRANSACT_RFCCALL function in the IS-H Industry-Specific Component Hospital subsystem in SAP Healthcare Industry Solution, and the SAP ERP central component (aka ECC 6), allows remote authenticated users to bypass intended transaction…

MEDIUM 6.5EPSS 1.62%

Does this matter?

Lower severity and a low EPSS score (1.62%). Track it; it rarely justifies an emergency change on its own.

Description

The ISHMED-PATRED_TRANSACT_RFCCALL function in the IS-H Industry-Specific Component Hospital subsystem in SAP Healthcare Industry Solution, and the SAP ERP central component (aka ECC 6), allows remote authenticated users to bypass intended transaction restrictions via unspecified vectors.

CVSS 2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
1.62% probability · 75th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
sap/erp central component · sap/healthcare industry solution
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.