Multiple vulnerabilities have been reported in SAP products which could allow an attacker to perform code injection, DOM-based Cross-Site Scripting (XSS), Server-Side Request Forgery (SSRF) and perform Sql injection attacks or cause denial of service condition on the targeted system.
Target Audience:
SAP system administrators, SAP security teams, IT infrastructure teams managing SAP landscape and Application developers using affected SAP.
Risk Assessment:
Code execution, data manipulation or disclosure, service disruption, redirection of users to malicious resources
Impact Assessment:
Execution of malicious code, potential for system compromise, unauthorized access, data exposure, high risk of data breach.
The information provided herein is on "as is" basis, without warranty of any kind.