SAP Knowledge Base Article - Preview

3764869 - SAP FC vulnerability CVE-2014-0759

Symptom

  • Request to confirm whether the product is affected by the CVE-2014-0759.
  • CVE-2014-0759 An Unquoted Windows Search Path vulnerability affecting Schneider Electric Floating License Manager versions 1.0.0 through 1.4.0. Because the service path is not properly quoted, a local user may exploit Windows path parsing behavior by placing a crafted executable in a specific location, which could then be executed with higher privileges. 


Read more...

Environment

  • SAP BusinessObjects Financial Consolidation (FC) 10.1.

Product

SAP Financial Consolidation 10.1

Keywords

cve-2013-1609, cve-2014-5455, CVE-2014-0759, security vulnerability, vulnerability assessment, financial consolidation, not impacted, components not used, bfc, epm-bfc, product security, cve impact, mitigation, workaround, confirmation , KBA , EPM-BFC-PSI , Performance, Stability, Installation , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.