Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential disclosure & modifctn of persistd data in SESA_ARC, SAP security note 1496671

SAP Note 1496671
SAP Security Note
High priority

SAP security note 1496671, "Potential disclosure & modification of persisted data in SESA_ARC", is a program error note released on 12.10.2010. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Information Lifecycle Management (ILM) > ESA Archiving (BC-ILM-APE)
CategoryProgram error
PriorityHigh priority
TypeSAP Security Note
StatusReleased for Customer
Released on12.10.2010

Description

Symptom

A malicious user can exploit certain methods or function modules in the package SESA_ARC and use specially crafted inputs to execute arbitrary database commands. This can lead to the retrieval, modification, or removal of data persisted by the system.

Solution

Import the Support Package assigned to this note. The affected methods and function modules are obsolete and are deactivated by this correction.

Reason and prerequisites

The vulnerability arises from an SQL injection flaw. The affected code constructs SQL statements using strings that can be manipulated by a malicious user. This allows the attacker to alter the SQL statement to retrieve additional information from the database or potentially modify it.

Full note on SAP: SAP Support Launchpad note 1496671

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More