The ABAP Help documentation and translation tools (BC-DOC-HLP) in Basis in SAP Netweaver ABAP Application Server does not properly restrict access, which allows local users to gain privileges and execute ABAP instructions via crafted help messages.
References
Configurations
Information
Published : 2014-04-30 07:22
Updated : 2014-05-09 21:06
NVD link : CVE-2014-3130
Mitre link : CVE-2014-3130
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
sap
- netweaver_abap_application_server