First published: Tue Jan 09 2018(Updated: )
In SAP Solution Manager 7.20, the role SAP_BPO_CONFIG gives the Business Process Operations (BPO) configuration user more authorization than required for configuring the BPO tools.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Solution Manager | =7.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-2361.
The severity of CVE-2018-2361 is high with a score of 8.8.
The affected software for CVE-2018-2361 is SAP Solution Manager 7.20.
The vulnerability in SAP Solution Manager 7.20 allows the role SAP_BPO_CONFIG to have more authorization than required for configuring the BPO tools, potentially leading to unauthorized access or misuse.
Yes, security patches and fixes for CVE-2018-2361 are available. Please refer to the SAP Security Patch Day January 2018 blog post and SAP Note 2507934 for more information.