Description
An authenticated user can use certain functions of SAP Solution Manager without the authenticated user having the required authorization. This may result in an escalation of privileges.
Available fix and Supported packages
- ST | 400 | 400
- ST | 710 | 710
- ST-PI | 2008_1_46C | 2008_1_46C
- ST-PI | 2005_1_46D | 2005_1_46D
- ST-PI | 2005_1_610 | 2005_1_610
- ST-PI | 2005_1_620 | 2008_1_620
- ST-PI | 2008_1_640 | 2008_1_640
- ST-PI | 2008_1_700 | 2008_1_700
- ST-PI | 2008_1_710 | 2008_1_710
Affected component
- SV-SMG-INS
Installation, Configuration and Upgrade of Solution Manager
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1513474