Description
An authenticated user can use functionality of class method GET_CONVERTED_TABLE to which access should be restricted. This can potentially result in an Escalation of Privileges.
Available fix and Supported packages
- SAP_ABA | 700 | 702
- SAP_ABA 702 | SAPKA70205 |
- SAP_ABA 701 | SAPKA70108 |
- SAP_ABA 700 | SAPKA70024 |
Affected component
- AP-MD-PRO
Product
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1497599