Description
This SAP Note has already been released as a normal SAP Note that is not a Security Note. No further activities are required if you have already implemented this SAP Note.
An authenticated user can use functions of SCM PDS Integration to which access should be restricted. This may result in an escalation of privileges.
Available fix and Supported packages
- SCM | 500 | 500
- SCM | 510 | 510
- SCM | 700 | 700
- SCM 700 | SAPKY70006 |
- SCM 500 | SAPKY50019 |
- SCM 510 | SAPKY51015 |
Affected component
- SCM-APO-INT-MD-PDS
Production Data Structure
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1429094