Description
Transaction FIAAHELP and the function module AA_CUS_EDIT_CONTENT can be used to change existing source code without an authorization check, among other things.
Available fix and Supported packages
- SAP_APPL | 470 | 470
- SAP_APPL | 500 | 500
- SAP_APPL | 600 | 600
- SAP_APPL | 602 | 602
- SAP_APPL | 603 | 603
Affected component
- FI-AA
Asset Accounting
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1342183