Description
A malicious user can trigger functionality in Manager Self Service (MSS) 60.1 without authentication and authorization.
Available fix and Supported packages
- BP_ERP4MSS | 60.1 | 60.1
- BP MSS 60.1 | SP005 | 000023
Affected component
- EP-PCT-MGR-HR
BP for Manager Self-Service (HR)
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1526079