SAP BTP Security Services Integration Library ([Python] sap-xssec) - versions < 4.1.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.
The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
Link | Tags |
---|---|
https://me.sap.com/notes/3411067 | vendor advisory permissions required |
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | vendor advisory |
https://pypi.org/project/sap-xssec/ | product |
https://blogs.sap.com/2023/12/12/unveiling-critical-security-updates-sap-btp-security-note-3411067/ | vendor advisory |
https://github.com/SAP/cloud-pysec/security/advisories/GHSA-6mjg-37cp-42x5 | vendor advisory |
https://github.com/SAP/cloud-pysec/ | product |