Home
MEDIUM: 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:LDefault status
unaffected
SAPSCORE 132
affected
S4CORE 102
affected
103
affected
104
affected
105
affected
106
affected
107
affected
108
affected
FI-CA 606
affected
616
affected
617
affected
618
affected
Description
SAP FICA ODN framework allows a high privileged user to inject value inside the local variable which can then be executed by the application. An attacker could thereby control the behaviour of the application causing high impact on integrity, low impact on availability and no impact on confidentiality of the application.
Problem types
CWE-94: Improper Control of Generation of Code
Product status
SAPSCORE 132
S4CORE 102
103
104
105
106
107
108
FI-CA 606
616
617
618