Description
The Shopping cart fields could be abused by a malicious user, who could modify displayed application content without authorization and potentially obtain authentication information from other legitimate users.
This note will fix the vulnerability of allowing code injection by malicious web users into the web pages viewed by other users and thus transfer of critical information can be prevented.
Available fix and Supported packages
- SRM_SERVER | 550 | 550
- SRM_SERVER 550 | SAPKIBKT17 |
Affected component
- SRM-EBP-TEC-ITS
ITS and Web files
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1347929