Description
Package S_CM_EXTRACT contains code which allows to execute arbitrary program code of the user#s choice.
A malicious user can therefore control the behavior of the system or can potentially escalate privileges by executing malicious code without legitimate own credentials.
Available fix and Supported packages
- PI_BASIS | 2005_1_640 | 2005_1_700
- PI_BASIS | 2006_1_640 | 2006_1_710
- PI_BASIS | 701 | 702
- PI_BASIS | 711 | 730
- PI_BASIS 702 | SAPK-70205INPIBASIS |
- PI_BASIS 2006_1_710 | SAPKIPYN11 |
- PI_BASIS 711 | SAPK-71106INPIBASIS |
- PI_BASIS 720 | SAPK-72004INPIBASIS |
- PI_BASIS 2005_1_640 | SAPKIPYJ6L |
- PI_BASIS 2006_1_640 | SAPKIPYL11 |
- PI_BASIS 2005_1_700 | SAPKIPYJ7N |
- PI_BASIS 2006_1_700 | SAPKIPYM13 |
- PI_BASIS 701 | SAPK-70108INPIBASIS |
- PI_BASIS 730 | SAPK-73001INPIBASIS |
Affected component
- CA-BFA-TRA
Transceiver
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1482180