Description
SAP Content Server contains code that changes the program’s behavior when a user is successfully authenticated with a certain user name. An attacker can be authenticated to SAP Content Server without having their own legitimate credentials, or they may escalate privileges.
Available fix and Supported packages
- CONTSERV | 6.50 | 6.50
- SAP CONTENT SERVER 6.50 | SP002 | 000000
Affected component
- BC-SRV-KPR-CS
SAP Content Server
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/2114025