Description
An attacker with special authorizations can manipulate objects in the area of the application component BW-BCT-TCT-IQM to change the displayed application content of another user without authorization, and possibly access authentication information of other legitimate users.
Available fix and Supported packages
- SAP_BW | 711 | 711
- SAP_BW | 730 | 730
- SAP_BW | 731 | 731
- SAP_BW 731 | SAPKW73101 |
- SAP_BW 730 | SAPKW73005 |
- SAP_BW 711 | SAPKW71109 |
Affected component
- BW-BCT-TCT-IQM
BW only – Information Quality Management
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1606438