SAP FICA ODN Framework Local Variable Injection Vulnerability Allowing Application Behavior Manipulation

Vulnerability

A vulnerability exists in the SAP FICA ODN framework, where a high-privileged user can inject values into local variables that the application can execute. This flaw allows an attacker to manipulate the application's behavior, significantly impacting its integrity, while only slightly affecting availability and not compromising confidentiality.

Impact

Exploitation of this vulnerability could lead to unauthorized manipulation of the application's behavior, causing significant integrity issues.

Remediation

Users are advised to review the SAP Security Notes related to this vulnerability and implement the recommended patches. SAP Security Notes can be accessed through the SAP for Me platform.

Added: Jul 23, 2025, 4:17 AM
Updated: Jul 23, 2025, 4:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
2.8
remediation
0.0
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.