Description
Flexible Solution Billing (FSB) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Some well-known impacts of Missing Authorization check are –
- abuse functionality restricted to a particular user group
- read, modify or delete restricted data
Available fix and Supported packages
- SOLINVE | 606 | 606
- SOLINVE | 607 | 607
- SOLINVE | 608 | 608
- SOLINVE 606 | SAPK-60603INSOLINVE |
- SOLINVE 608 | SAPK-60801INSOLINVE |
- SOLINVE 607 | SAPK-60704INSOLINVE |
Affected component
- SD-BIL-IV-CB
Consolidated Billing
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/2355398