Description
Certain reports that do not have an authorization check can create or change transport requests and change the piece list of a request.
This is a security breach.
Available fix and Supported packages
- SAP_BASIS | 46C | 46D
- SAP_BASIS | 610 | 640
- SAP_BASIS | 700 | 701
- SAP_BASIS | 710 | 720
- SAP_BASIS 46C | SAPKB46C58 |
- SAP_BASIS 620 | SAPKB62066 |
- SAP_BASIS 640 | SAPKB64024 |
- SAP_BASIS 710 | SAPKB71008 |
- SAP_BASIS 711 | SAPKB71102 |
- SAP_BASIS 700 | SAPKB70019 |
- SAP_BASIS 701 | SAPKB70104 |
Affected component
- BC-CTS-ORG
Workbench/Customizing Organizer
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1304803