Description
A malicious user can exploit PRA(Production and revenue accounting) using specially crafted inputs to execute arbitrary database commands to retrieve, modify, or remove data persisted by the system.
Available fix and Supported packages
- IS-OIL | 600 | 600
- IS-OIL | 602 | 602
- IS-OIL | 603 | 603
- IS-PRA | 604 | 604
- IS-PRA | 605 | 605
- IS-OIL 600 | SAPK-60019INISOIL |
- IS-OIL 602 | SAPK-60209INISOIL |
- IS-OIL 603 | SAPK-60308INISOIL |
- IS-PRA 604 | SAPK-60409INISPRA |
- IS-PRA 605 | SAPK-60503INISPRA |
Affected component
- IS-OIL-PRA
Production and Revenue Accounting
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1509344