Description
An authenticated user can access objects of Integration Directory to which access should be restricted. This can potentially result in an Escalation of Privileges.
Available fix and Supported packages
- SAP_XIESR | 7.11 | 7.11
- SAP_XITOOL | 7.11 | 7.11
- ESR 7.11 | SP002 | 000013
- ESR 7.11 | SP003 | 000016
- ESR 7.11 | SP004 | 000010
- ESR 7.11 | SP005 | 000030
- ESR 7.11 | SP006 | 000000
- XI TOOLS 7.11 | SP002 | 000012
- XI TOOLS 7.11 | SP003 | 000016
- XI TOOLS 7.11 | SP004 | 000010
- XI TOOLS 7.11 | SP005 | 000001
- XI TOOLS 7.11 | SP006 | 000000
Affected component
- BC-XI-IBD
Integration Builder – Design
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1465993