Security Note
High Priority
SAP security note 1493234, "Potential Disclosure and Modification of Persisted Data", is a note released on October 12, 2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can exploit specially crafted inputs to execute arbitrary database commands to retrieve, modify, or remove data persisted by the system.
Solution
Apply the correction instructions provided in the SAP Security Note.
Reason and prerequisites
The vulnerability is caused by an SQL injection issue. The code constructs SQL statements by including user-controllable strings, allowing malicious manipulation to retrieve or modify database information.
References
- SAP Note 1495437: Error when calling function module in method SELECT_COUNT
Affected components
- EA-PS: 603, 604, 605
Full note on SAP: SAP Support Launchpad note 1493234
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
