Description
The following two issues are possible:
1. The SAP Retail Store can be abused by a malicious user, allowing them to modify displayed application content without authorization, and to potentially obtain authentication information from other legitimate users.
2. The SAP Retail Store can be abused by a malicious user, allowing them to modify application content, persist the modified content without authorization, and to potentially obtain authentication information from other legitimate users.
Available fix and Supported packages
- SAP_APPL | 46C | 46C
- SAP_APPL | 470 | 470
- EA-RETAIL | 110 | 110
- EA-RETAIL | 200 | 200
- SAP_APPL 470 | SAPKH47036 |
- SAP_APPL 46C | SAPKH46C63 |
- EA-RETAIL 110 | SAPKGPRA32 |
- EA-RETAIL 200 | SAPKGPRB21 |
Affected component
- LO-SRS
SAP Retail Store
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1524777