Description
This security note has been updated.
For more detailed information, see Security Note 1769046.
An authenticated user can use the function module DISPATCH_SPML_REQUEST_BGRFC to which access should be restricted. This may result in an escalation of privileges.
Available fix and Supported packages
- SAP_BASIS | 702 | 702
- SAP_BASIS | 720 | 730
- SAP_BASIS | 731 | 731
- SAP_BASIS 731 | SAPKB73103 |
- SAP_BASIS 720 | SAPKB72008 |
- SAP_BASIS 702 | SAPKB70212 |
- SAP_BASIS 730 | SAPKB73008 |
Affected component
- BC-SEC-USR-ADM
Users and Authorization administration
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1661157