Description
This security note has been updated. For more detailed information, see Security Note 1601461.
User inputs in Internet applications should not execute through conversion in a Web application.
Available fix and Supported packages
- SAP_BASIS | 620 | 640
- SAP_BASIS | 700 | 702
- SAP_BASIS | 710 | 730
- SAP_BASIS | 731 | 731
- SAP_BASIS 640 | SAPKB64014 |
- SAP_BASIS 700 | SAPKB70005 |
- SAP_BASIS 640 | SAPKB64015 |
- SAP_BASIS 700 | SAPKB70006 |
- SAP_BASIS 640 | SAPKB64016 |
- SAP_BASIS 640 | SAPKB64019 |
- SAP_BASIS 700 | SAPKB70011 |
Affected component
- BC-SEC
Security – Read KBA 2985997 for subcomponents
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/866020