Home
CRITICAL: 9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HDefault status
unaffected
SCMAPO 713
affected
714
affected
S4CORE 102
affected
103
affected
104
affected
S4COREOP 105
affected
106
affected
107
affected
108
affected
SCM 700
affected
701
affected
702
affected
712
affected
Description
SAP S/4HANA and SAP SCM Characteristic Propagation has remote code execution vulnerability. This allows an attacker with user level privileges to create a new report with his own code potentially gaining full control of the affected SAP system causing high impact on confidentiality, integrity, and availability of the application.
Problem types
CWE-94: Improper Control of Generation of Code
Product status
SCMAPO 713
714
S4CORE 102
103
104
S4COREOP 105
106
107
108
SCM 700
701
702
712