Incomplete in the CWE catalog · 9 CVEs mapped
The product stores sensitive information in a file system or device that does not have built-in access control.
🚨 A misconfigured authentication system in SAP Financial Consolidation is the key to an open door—anyone could access the Admin account without a password! 🔥 Think of it like a five-star restaurant where the front door is wide open, and the host isn't even checking who walks in—everyone's welcome to the VIP kitchen without a reservation! An attacker could stroll in and wreak havoc—alter financial records, expose sensitive data, or even disrupt operations entirely. With the integrity and confidentiality of your financial data at stake, this vulnerability poses an absolutely devastating threat to your organization!
Insecure file retrieval process that facilitates potential for file manipulation to affect product stability and confidentiality, integrity, authenticity, and attestation of stored data.
Use of Hard-coded Credentials, Storage of Sensitive Data in a Mechanism without Access Control vulnerability in E-Kent Pallium Vehicle Tracking allows Authentication Bypass. This issue affects Pallium Vehicle Tracking: before 17.10.2024.