CVE-2013-3061: SAP ERP Central Component

Medium severity, CVSS 6.5. EPSS: 1.6% chance of exploitation in the next 30 days.

The ISHMED-PATRED_TRANSACT_RFCCALL function in the IS-H Industry-Specific Component Hospital subsystem in SAP Healthcare Industry Solution, and the SAP ERP central component (aka ECC 6), allows remote authenticated users to bypass intended transaction restrictions via unspecified vectors.

Affected products

  • SAP ERP Central Component: affected versions not specified
  • SAP Healthcare Industry Solution: affected versions not specified

Published 2013-05-01. Last modified 2026-06-16.