Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

SEC-102_01 ‘SQL-Injection’ Package VVSRFISL, SAP security note 1597776

SAP Note 1597776
SAP Security Note
High priority

SAP security note 1597776, "SEC-102_01 ‘SQL-Injection’: Package VVSRFISL", is a program error note released on April 13, 2012. Below are the symptom and SAP recommended solution.

ComponentFinancial Services > Statutory Reporting for Insurancies (FS-SR)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released onApril 13, 2012
LanguageEnglish

Description

Symptom

Potential disclosure of persisted data in Statutory Reporting [FS-SR].

Solution

Please implement the attached correction instruction or the corresponding support package. This note disables obsolete code. No testing is required after applying the note.

  • Class: ISSR_MIG_SERVICES_BCK
  • Method: CONV_MAKE_BCK_SGL
  • Parameter: IV_SOURCE_TAB

Reason and prerequisites

The problem is caused by an SQL injection vulnerability. The code composes an SQL statement that contains strings that can be altered by a malicious user. The manipulated SQL statement can then be used to retrieve data from the database.

CVSS

Score 0

Full note on SAP: SAP Support Launchpad note 1597776

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More