SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid repository user. This is an unauthenticated functionality that you can use on windows machines to do SMB relaying.
2018-08-14T16:29:01.427
2024-11-21T04:03:50.110
Modified
CVSSv3.0: 8.6 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | sap | supplier_relationship_management_mdm_catalog | 3.73 | Yes |
| Application | sap | supplier_relationship_management_mdm_catalog | 7.31 | Yes |
| Application | sap | supplier_relationship_management_mdm_catalog | 7.32 | Yes |