Skip links

CSRF vulnerability in Web Page Composer, SAP security note 1637611

Description

An attacker can execute functions in Web Page Composer without authentication and authorization.

Available fix and Supported packages

  • KMC-WPC | 7.00 | 7.02
  • KMC-WPC | 7.30 | 7.30
  • KMC-WPC | 7.31 | 7.31
  • KMC WEB PAGE COMPOSER 7.00 | SP022 | 000002
  • KMC WEB PAGE COMPOSER 7.00 | SP023 | 000002
  • KMC WEB PAGE COMPOSER 7.00 | SP024 | 000002
  • KMC WEB PAGE COMPOSER 7.00 | SP025 | 000001
  • KMC WEB PAGE COMPOSER 7.00 | SP026 | 000000
  • KMC WEB PAGE COMPOSER 7.01 | SP007 | 000005
  • KMC WEB PAGE COMPOSER 7.01 | SP008 | 000003
  • KMC WEB PAGE COMPOSER 7.01 | SP009 | 000002
  • KMC WEB PAGE COMPOSER 7.01 | SP010 | 000001
  • KMC WEB PAGE COMPOSER 7.01 | SP011 | 000000
  • KMC WEB PAGE COMPOSER 7.02 | SP004 | 000001
  • KMC WEB PAGE COMPOSER 7.02 | SP005 | 000001
  • KMC WEB PAGE COMPOSER 7.02 | SP006 | 000001
  • KMC WEB PAGE COMPOSER 7.02 | SP007 | 000001
  • KMC WEB PAGE COMPOSER 7.02 | SP008 | 000001
  • KMC WEB PAGE COMPOSER 7.02 | SP009 | 000001
  • KMC WEB PAGE COMPOSER 7.02 | SP010 | 000001
  • KMC WEB PAGE COMPOSER 7.02 | SP011 | 000000
  • KMC WEB PAGE COMPOSER 7.30 | SP001 | 000002
  • KMC WEB PAGE COMPOSER 7.30 | SP002 | 000002

Affected component

    EP-PIN-WPC-WCM
    Web Content Mgmt (Content Library, Web Resources, KM Integ.)

CVSS

Score: 0

Exploit

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1637611

TAGS

#Cross-site-request-forgery
#XSRF
#WPC
#Web-Page-Composer

How to detect over 4100 vulnerabilities in SAP Systems?

More to explorer

SAP Cloud Connector Certificate Validation Issue

Date of Release: February 13, 2024 Advisory ID: CVE-2024-25642 Affected Software: SAP Cloud Connector Versions Affected: 2.15.0 to 2.16.1 Vulnerability Summary:A critical vulnerability,