Description
A malicious user can exploit FI-CAX (Extended FI-CA) and use specially crafted inputs to modify database commands, resulting in the retrieval of additional information persisted by the system.
Available fix and Supported packages
- FI-CAX | 471 | 471
- FI-CAX | 472 | 472
- FI-CAX | 600 | 600
- FI-CAX | 602 | 602
- FI-CAX | 603 | 603
- FI-CAX | 604 | 604
- FI-CAX | 605 | 605
- FI-CAX 471 | SAPKIPRB27 |
- FI-CAX 472 | SAPKIPRC21 |
- FI-CAX 600 | SAPK-60020INFICAX |
- FI-CAX 602 | SAPK-60210INFICAX |
- FI-CAX 603 | SAPK-60309INFICAX |
- FI-CAX 604 | SAPK-60410INFICAX |
- FI-CAX 605 | SAPK-60505INFICAX |
Affected component
- FI-CAX
Non-industry specific contract accounts receivable, payable
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1592430