Description
This security note has been updated. For more detailed information, see Security Note 1572613.
Program UAC_ASSIGNMENT_CONTROL_TEST contains code which allows to execute arbitrary program code of the user’s choice.
A malicious user can therefore control the behavior of the system or can potentially escalate privileges by executing malicious code without legitimate own credentials.
Available fix and Supported packages
- FINBASIS | 300 | 300
- FINBASIS | 600 | 600
- FINBASIS | 700 | 700
- FINBASIS | 602 | 602
- FINBASIS | 603 | 603
- FINBASIS | 604 | 604
- FINBASIS | 605 | 605
- FINBASIS 300 | SAPK-30026INFINBASIS |
- FINBASIS 700 | SAPK-70013INFINBASIS |
- FINBASIS 604 | SAPK-60410INFINBASIS |
Affected component
- FIN-FB
Financials Basis
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1493809