Description
An attacker can execute functions in XMLForms without authentication and authorization.
Available fix and Supported packages
- KMC-CM | 7.00 | 7.02
- KMC-CM | 7.30 | 7.30
- KMC-CM | 7.31 | 7.31
- EP-CM | 6.0_640 | 6.0_640
- CM+COLLABORATION 6.0_640 | SP025 | 000008
- CM+COLLABORATION 6.0_640 | SP026 | 000008
- CM+COLLABORATION 6.0_640 | SP027 | 000005
- CM+COLLABORATION 6.0_640 | SP028 | 000002
- CM+COLLABORATION 6.0_640 | SP029 | 000000
- KMC CONTENT MANAGEMENT 7.00 | SP021 | 000010
- KMC CONTENT MANAGEMENT 7.00 | SP022 | 000008
- KMC CONTENT MANAGEMENT 7.00 | SP023 | 000004
- KMC CONTENT MANAGEMENT 7.00 | SP024 | 000002
- KMC CONTENT MANAGEMENT 7.00 | SP025 | 000002
- KMC CONTENT MANAGEMENT 7.00 | SP026 | 000000
- KMC CONTENT MANAGEMENT 7.01 | SP007 | 000007
- KMC CONTENT MANAGEMENT 7.01 | SP008 | 000005
- KMC CONTENT MANAGEMENT 7.01 | SP009 | 000002
- KMC CONTENT MANAGEMENT 7.01 | SP010 | 000002
- KMC CONTENT MANAGEMENT 7.01 | SP011 | 000000
- KMC CONTENT MANAGEMENT 7.02 | SP004 | 000004
- KMC CONTENT MANAGEMENT 7.02 | SP005 | 000003
- KMC CONTENT MANAGEMENT 7.02 | SP006 | 000006
- KMC CONTENT MANAGEMENT 7.02 | SP007 | 000003
Affected component
- EP-KM-TLS-XFB
XF Builder
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1638161