Description
An attacker can exploit Posting Lock Management and use specially crafted inputs to modify database commands, resulting in the retrieval of additional information persisted by the system.
Available fix and Supported packages
- FSAPPL | 100 | 100
- FSAPPL | 200 | 200
- FSAPPL | 300 | 300
- FSAPPL | 400 | 400
- FSAPPL 100 | SAPKISC218 |
- FSAPPL 400 | SAPK-40009INFSAPPL |
- FSAPPL 200 | SAPKISC325 |
- FSAPPL 300 | SAPK-30018INFSAPPL |
Affected component
- FS-AM-PLM
Posting Lock Management
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1880561