SAP security note 2519622, "Email Spoofing Vulnerability in SAP CRM IC WebClient". Below are the SAP recommended solution and the affected software components.
Description
Solution
To mitigate this vulnerability, apply the relevant Support Package or follow the manual correction instructions provided in the security note.
For detailed instructions and additional support packages, visit the SAP Support Portal.
CVSS
Score 5.4 Vector: AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
References
Referenced by
- SAP Note 2576032 – addresses additional related issues
Affected components
- CRM-IC-CHA-EMA (700, 701, 702, 712, 713, 714, 730)
Full note on SAP: SAP Support Launchpad note 2519622
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
