Description
When calling Transaction FIBF (Menu Business Transaction Events), you can enter any transaction name in the okcode field and the system executes the transaction without a transaction authorization check.
Available fix and Supported packages
- SAP_ABA | 46B | 46B
- SAP_ABA | 46C | 46C
- SAP_ABA | 620 | 620
- SAP_ABA | 640 | 640
- SAP_ABA | 700 | 700
- SAP_ABA | 710 | 710
- SAP_ABA 700 | SAPKA70005 |
- SAP_ABA 640 | SAPKA64015 |
- SAP_ABA 620 | SAPKA62056 |
Affected component
- CA-GTF-TS-BRHF
Basis related Help Functions
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/879342