Due to a missing authorization check in an obsolete RFC enabled function module in SAP BASIS, an authenticated low-privileged attacker could call a Remote Function Call (RFC), potentially accessing restricted system information. This results in low impact on confidentiality, with no impact on integrity or availability of the application.
| Software | From | Fixed in |
|---|---|---|
| sap / sap_basis | 700 | 700.x |
| sap / sap_basis | 701 | 701.x |
| sap / sap_basis | 702 | 702.x |
| sap / sap_basis | 731 | 731.x |
| sap / sap_basis | 740 | 740.x |
| sap / sap_basis | 750 | 750.x |
| sap / sap_basis | 751 | 751.x |
| sap / sap_basis | 752 | 752.x |
| sap / sap_basis | 753 | 753.x |
| sap / sap_basis | 754 | 754.x |