Description
A malicious user can trigger functionality in PPM-PRO/cProjects without authentication and authorization.
Available fix and Supported packages
- CPROJECTS | 300 | 300
- CPROJECTS | 310_620 | 310_640
- CPRXRPM | 400 | 400
- CPROJECTS 310_620 | SAPK-31220INCPROJECT |
- CPROJECTS 310_640 | SAPK-31420INCPROJECT |
- CPRXRPM 400 | SAPK-40019INCPRXRPM |
Affected component
- PPM-PRO
Project Management
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1523140