Description
PRA contains code which allows to execute arbitrary program code of the user’s choice.
A malicious user can therefore control the behavior of the system or can potentially escalate privileges by executing malicious code without legitimate own credentials.
Available fix and Supported packages
- IS-PRA | 605 | 605
Affected component
- IS-OIL-PRA
Production and Revenue Accounting
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1509807