Description
An un-authorized user can trigger functionality in SAP ME MFG
5.2 on behalf of an unsuspecting authorized user by fooling the unsuspecting user to trigger a URL callback via a script or special HTML element parameter.
Available fix and Supported packages
- VISIPRISEMFG | 520 | 520
Affected component
- MFG-ME
SAP Manufacturing Execution
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1536474