Medium priority
SAP security note 2647714, "[CVE-2018-2483] HTTP Verb Tampering vulnerability in SAP BI CMC", is a program error note released on November 13, 2018. Below are the symptom and the affected software components.
Description
Symptom
SAP has released this security note addressing a HTTP Verb Tampering vulnerability in the SAP Business Intelligence Central Management Console (CMC). This vulnerability allows an attacker to manipulate request methods, potentially impacting the security of the BI platform.
CVSS
Score 4.3/10 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected components
- ENTERPRISE (410, 420)
Full note on SAP: SAP Support Launchpad note 2647714
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
