SAP CRM (WebClient UI) - versions S4FND 102, 103, 104, 105, 106, 107, WEBCUIF, 700, 701, 731, 730, 746, 747, 748, 800, 801, allows an authenticated attacker to modify HTTP verbs used in requests to the web server. This application is exposed over the network and successful exploitation can lead to exposure of form fields
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/3269352 | Permissions Required |
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: sap
Published: 2023-04-11T03:11:30.554Z
Updated: 2023-04-11T20:16:30.045Z
Reserved: 2023-04-03T09:22:43.158Z
Link: CVE-2023-29189
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-04-11T04:16:09.283
Modified: 2023-04-18T19:12:51.917
Link: CVE-2023-29189
JSON object: View
Redhat Information
No data.
CWE