SAP Security Note
High priority
SAP security note 1496671, "Potential disclosure & modification of persisted data in SESA_ARC", is a program error note released on 12.10.2010. Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can exploit certain methods or function modules in the package SESA_ARC and use specially crafted inputs to execute arbitrary database commands. This can lead to the retrieval, modification, or removal of data persisted by the system.
Solution
Import the Support Package assigned to this note. The affected methods and function modules are obsolete and are deactivated by this correction.
Reason and prerequisites
The vulnerability arises from an SQL injection flaw. The affected code constructs SQL statements using strings that can be manipulated by a malicious user. This allows the attacker to alter the SQL statement to retrieve additional information from the database or potentially modify it.
Full note on SAP: SAP Support Launchpad note 1496671
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
