Description
By executing an internal standalone report, an attacker can display data from database tables even though he does not have the relevant authorization.
Available fix and Supported packages
- FINBASIS | 200 | 200
- FINBASIS | 300 | 300
- FINBASIS | 600 | 600
- FINBASIS | 700 | 700
- FINBASIS | 602 | 602
- FINBASIS | 603 | 603
- FINBASIS | 604 | 604
- FINBASIS | 605 | 605
- FINBASIS 600 | SAPK-60018INFINBASIS |
- FINBASIS 602 | SAPK-60208INFINBASIS |
- FINBASIS 603 | SAPK-60307INFINBASIS |
- FINBASIS 605 | SAPK-60502INFINBASIS |
- FINBASIS 300 | SAPK-30026INFINBASIS |
- FINBASIS 604 | SAPK-60408INFINBASIS |
- FINBASIS 700 | SAPK-70013INFINBASIS |
Affected component
- FIN-FB-MDF
Master Data Framework
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1489976