Description
IDoc inbound processing via HTTP or SOAP that is not required takes place if the relevant ICF services were incorrectly activated and the IDoc authorization that was granted was not restrictive enough.
Available fix and Supported packages
- SAP_BASIS | 620 | 640
- SAP_BASIS | 700 | 702
- SAP_BASIS | 710 | 730
- SAP_BASIS | 731 | 731
- SAP_BASIS | 72L | 800
Affected component
- BC-MID-ALE
Integration Technology ALE
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1487606