Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential disclosure of data in object data exchange monitor, SAP security note 1483158

SAP Note 1483158SAP Security NoteHigh priority

SAP security note 1483158, "Potential disclosure of data in object data exchange monitor", is a program error note released on September 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCustomer Relationship Management > Master Data > Products > Objects > Data Exchange
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released onSeptember 14, 2010
LanguageEnglish

Description

Symptom

A malicious user can exploit the object data exchange monitor and use specially crafted inputs to execute arbitrary database commands to retrieve data persisted by the system.

Solution

Implement the correction instructions for your release. You can Download for SNOTE or access the PDF Version.

Reason and prerequisites

The problem is caused by an SQL injection vulnerability. The code composes an SQL statement including strings that can be altered by a malicious user. The manipulated SQL statement can then be used to retrieve additional information from the database.

References

Affected components

  • BBPCRM 500
  • BBPCRM 520
  • BBPCRM 600
  • BBPCRM 700
  • BBPCRM 701

Full note on SAP: SAP Support Launchpad note 1483158

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More