Description
A malicious user can exploit programs FPB_COPY_FPB_USER, FPB_EXPORT_FPB_USER and FPB_IMPORT_FPB_USER and use specially crafted inputs to execute arbitrary database commands to retrieve, modify, or remove data persisted by the system.
Available fix and Supported packages
- EA-APPL | 500 | 500
- SAP_BASIS | 710 | 730
- SAP_ABA | 700 | 702
- EA-APPL 500 | SAPKGPAC24 |
- SAP_BASIS 710 | SAPKB71011 |
- SAP_BASIS 711 | SAPKB71106 |
- SAP_BASIS 720 | SAPKB72004 |
- SAP_BASIS 730 | SAPKB73001 |
- SAP_ABA 702 | SAPKA70205 |
- SAP_ABA 700 | SAPKA70023 |
- SAP_ABA 701 | SAPKA70108 |
Affected component
- BC-MUS-FPB
Personalization Framework
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1495272