CVE-2017-14511 describes a bypass vulnerability in SAP E-Recruiting versions 605 through 617, allowing attackers to register and confirm email addresses they do not own. This issue stems from predictable candidate_hrobject values and improper validation of corr_act_guid. With a CVSS score of 7.5 (HIGH), this vulnerability has a network attack vector, low attack complexity, and high impact on availability, as attackers can prevent legitimate users from registering by monopolizing email addresses. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not known to be actively exploited, with minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
605CPE matchmatch criteria | cpe:2.3:a:sap:e-recruiting:605:*:*:*:*:*:*:* | ||
606CPE matchmatch criteria | cpe:2.3:a:sap:e-recruiting:606:*:*:*:*:*:*:* | ||
616CPE matchmatch criteria | cpe:2.3:a:sap:e-recruiting:616:*:*:*:*:*:*:* | ||
617CPE matchmatch criteria | cpe:2.3:a:sap:e-recruiting:617:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.