Description
A user might use the FM SPP02_INVOICE_HEADERDETAIL and SPP02_INVOICE_DETAIL even if he has no authority to see the data provided by the FM.
Available fix and Supported packages
- ECC-DIMP | 606 | 606
- ECC-DIMP | 616 | 616
- ECC-DIMP | 617 | 617
- ECC-DIMP 617 | SAPK-61706INECCDIMP |
- ECC-DIMP 606 | SAPK-60614INECCDIMP |
- ECC-DIMP 616 | SAPK-61609INECCDIMP |
Affected component
- IS-A
Automotive
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/2028559