SAP security note 1497451, “Possible disclosure of saved data in FIN-SEM BPS”, is a note. Below is the security information published by SAP for this note.
Description
Symptom
An attacker can use targeted entries to prompt SEM planning to disclose additional data or change saved data in the database.
Reason and prerequisites
The problem occurs due to an SQL injection issue. In the code, an SQL statement is composed of strings, and an attacker can gain control over the content of a substring. This means that the resulting overall statement can be manipulated and data can be changed in the database, or the database can be prompted to disclose additional data.
Solution
Implement the corrections.
Affected Software Components:
- SEM-BW (Versions: 350, 400, 600, 700, 602, 603, 604, 605, 634)
Support Package:
Download Links:
- Download for SNOTE
- PDF Version
Translation Availability:
- Deutsch (Origin)
- 日本語
- Português (Machine Translation)
- Español (Machine Translation)
- Français (Machine Translation)
- Italiano (Machine Translation)
- Русский (Machine Translation)
- 中文 (Machine Translation)
- 한국어 (Machine Translation)
References: This document does not currently reference other SAP Notes or KBAs, nor is it referenced by other documents.
Full note on SAP: SAP Support Launchpad note 1497451
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
