Description
A malicious user can exploit IS-AFS and use specially crafted inputs to execute arbitrary database commands to retrieve, modify, or remove data persisted by the system.
Available fix and Supported packages
- P3A | V500 | V500
- P3A | V600 | V600
- P3A | V603 | V603
- P3A | V604 | V604
- P3A V604 | SAPK-60404INP3A |
- P3A V500 | SAPKIAF513 |
- P3A V603 | SAPK-60306INP3A |
Affected component
- IS-AFS-ARUN
Allocation Run
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1486048