Description
An un-authorized user can trigger functionality in MDSD Admin Console on behalf of an unsuspecting authorized user by fooling the unsuspecting user to trigger a URL callback via a script or special HTML element parameter.
Available fix and Supported packages
- MBA-DSD | 2.1 | 2.1
- MBA-DSD | 3.0 | 3.0
- MBA-DSD | 4.0 | 4.0
- MDSDADMINCONSOLE | 4.0 | 4.0
- MDSD 3.0 | SP003 | 000000
- MDSD 4.0 | SP001 | 000000
- XMDSD 2.1 | SP001 | 000023
- XMDSD 2.1 | SP002 | 000011
- XMDSD 2.1 | SP003 | 000000
Affected component
- XX-INT-APP-SEC-SCP
Security questions & issues in applications (Cloud Platform)
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1582983