Description
A malicious user can trigger functionality in bill of services without authentication and authorization. The user will be able to create new service entry sheets.
Available fix and Supported packages
- ECC-DIMP | 500 | 500
- ECC-DIMP | 600 | 600
- ECC-DIMP | 602 | 602
- ECC-DIMP | 603 | 603
- ECC-DIMP | 604 | 604
- ECC-DIMP | 605 | 605
- ECC-DIMP 600 | SAPK-60019INECCDIMP |
- ECC-DIMP 500 | SAPKIPMH14 |
- ECC-DIMP 602 | SAPK-60209INECCDIMP |
- ECC-DIMP 603 | SAPK-60308INECCDIMP |
- ECC-DIMP 604 | SAPK-60409INECCDIMP |
- ECC-DIMP 605 | SAPK-60503INECCDIMP |
Affected component
- IS-ADEC-BOQ
Bill of Quantity
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1511594