Description
A malicious user can trigger functionality in CA-GTF-WFA (WFM) without authentication and authorization.
Available fix and Supported packages
- ISRWFM | 100 | 100
- ISRWFM | 310 | 310
- ITIMECLOCK | 200 | 200
- ITIMECLOCK | 310 | 310
- ISR WORKFORCE MANAGEMENT 1.0 | SP012 | 000000
- ISR WORKFORCE MANAGEMENT 3.1 | SP006 | 000000
- ITIME CLOCK SERVER 2.0 | SP012 | 000000
- ITIME CLOCK SERVER 3.1 | SP006 | 000000
Affected component
- CA-GTF-WFA
please use CRM-WFD(Workforce Management Application)
CVSS
Score: 0
Exploit
Exploit is not available.
For detailed information please contact the mail [email protected].
URL
https://launchpad.support.sap.com/#/notes/1511031