Description
A malicious user can exploit SuPM v1.0 and use specially crafted inputs to modify data-base commands, resulting in the retrieval of additional information persisted by the system.
Available fix and Supported packages
- SR_CORE | 100 | 100
- SR_CORE 100 | SAPK-10006INSRCORE |
Affected component
- GRC-SPM-SR
Sustainability Reporting
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1517670