Description
ITS 6.20 allows to disable services with the ITS admin tool. If a service is disabled it can’t be called by a user. Unfortunately disabling don’t work for the technical service global. This ITS service normally cannot be called. Its only purpose is to hold global information which are inherited by all other services. If a URL http://host.domain:port/scripts/wgate/global/! is called by a user the logon page appears. This might be unwanted by customers who disable all unused services. An attacker could not do more than what he could do on any ITS logon page.
Available fix and Supported packages
- BC-FES-ITS | 620 | 620
Affected component
- BC-FES-ITS
SAP Internet Transaction Server
CVSS
Score: 0
Exploit
Exploit is not available.
For detailed information please contact the mail [email protected].
URL
https://launchpad.support.sap.com/#/notes/883908