SAP security note 1588882, “Potential modification or disclosure of persisted data in CO”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can exploit the Account Assignment Manager in the Controlling module for costs and revenue by using specially crafted inputs to modify database commands. This vulnerability allows unauthorized retrieval of additional information or modification of data persisted by the system.
Solution
Implement the attached program corrections to ensure the system performs additional authorization checks and verifies that the data being transferred aligns with the customizing for the Account Assignment Manager.
CVSS
Score 0
References
Affected components
- SAP_APPL 600
- SAP_APPL 602
- SAP_APPL 603
- SAP_APPL 604
- SAP_APPL 605
- PI 2004_1_46B to 2004_1_500
Full note on SAP: SAP Support Launchpad note 1588882
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
