Description
This security note has been updated. For more detailed information, see Security Note 1640676.
An un-authorized user can trigger functionality in the Web Communication Layer for Event Management (WCL) on behalf of an unsuspecting authorized user.
Available fix and Supported packages
- SAP-EM-WCL | 510 | 510
- SAP-EM-WCL | 700 | 700
- SAP-SCMWCL | 500 | 500
- SAP-SCMWCL | 410 | 410
- SAP EM-WCL 5.1 | SP016 | 000000
- SAP EM-WCL 7.0 | SP006 | 000000
- SAP SCM WCL 4.1 | SP021 | 000000
- SAP SCM WCL 5.0 | SP018 | 000001
Affected component
- SCM-EM-MGR-ISQ
Information System and Queries
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1519463