Description
On installation of SAP ERP Client for E-Bilanz 1.0, Incorrect default filesystem permissions are set in its installation folder which allows anyone to modify the files in the folder.
Available fix and Supported packages
- EBILANZ | 100 | 100
- E-BILANZ CLIENT 1.0 | SP003 | 000012
Affected component
- EPM-EBI
SAP ERP Client For E-Bilanz
CVSS
Score: 4.4
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/2971112