Description
A malicious user can exploit class /SAPAPO/CL_GEN_DB_WRITE_CS, method WRITE_DB_CLIENT_SPECIFIED and use specially crafted inputs to execute arbitrary database commands to retrieve, modify, or remove data persisted by the system.
Available fix and Supported packages
- SCM_BASIS | 700 | 700
- SCM_BASIS | 701 | 701
- SCM_BASIS 701 | SAPK-70102INSCMBASIS |
- SCM_BASIS 700 | SAPK-70009INSCMBASIS |
Affected component
- SCM-BAS-MD-TL
Transportation Lanes, TSP Profile and Planning Costs
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1494335