First published: Tue May 12 2020(Updated: )
The use of an admin backend report within SAP Master Data Governance, versions - S4CORE 101, S4FND 102, 103, 104, SAP_BS_FND 748; allows an attacker to execute crafted database queries, exposing the backend database, leading to SQL Injection.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Master Data Governance \(s4core\) | =101 | |
Sap Master Data Governance \(s4fnd\) | =102 | |
Sap Master Data Governance \(s4fnd\) | =103 | |
Sap Master Data Governance \(s4fnd\) | =104 | |
Sap Master Data Governance \(sap Bs Fnd\) | =748 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.