High priority
SAP security note 1589641, "Update #1 to Security Note 1411659", is released on 25.05.2011. Below are the SAP recommended solution and the affected software components.
Description
Solution
Apply the automatic correction instructions PMEK026271 & PMEK029538 provided in Security Note 1411659.
Reason and prerequisites
Security Note 1411659 was missing correction instructions necessary to fully mitigate the identified vulnerability.
Affected components
- Supplier Relationship Management > Supplier Self-Services (SRM-SUS)
- Vendor Evaluation (SRM-EBP-VE)
- Supplier Registration (SRM-ROS)
Full note on SAP: SAP Support Launchpad note 1589641
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
