Description
The Apache Tomcat server delivered with SAP CRM Mobile Sales, which is required by the IPC (Internet Pricing & Configuration) user interface is accessible from the network. It could be abused by a malicious user on the network to read and modify data.
Available fix and Supported packages
- APACHETOMCAT | 6.0 | 6.0
- APACHETOMCAT | 5.5 | 5.5
Affected component
- CRM-MSA-IPC-CFG
Use CRM-MSA(IPC Configuration)
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1525994