First published: Wed May 01 2013(Updated: )
The ISHMED-PATRED_TRANSACT_RFCCALL function in the IS-H Industry-Specific Component Hospital subsystem in SAP Healthcare Industry Solution, and the SAP ERP central component (aka ECC 6), allows remote authenticated users to bypass intended transaction restrictions via unspecified vectors.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP ERP central component | ||
SAP Healthcare Industry Solution |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3061 has been classified as a medium severity vulnerability due to its potential for privilege escalation.
To fix CVE-2013-3061, ensure that you apply the latest security patches provided by SAP for the affected components.
CVE-2013-3061 affects remote authenticated users of the SAP ERP Central Component and SAP Healthcare Industry Solution.
CVE-2013-3061 is a privilege escalation vulnerability allowing users to bypass transaction restrictions.
Yes, CVE-2013-3061 can be exploited by remote authenticated users to gain unauthorized access.