Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential modification/disclosure of persisted data i.CRM-IU, SAP security note 1590863

SAP Note 1590863

SAP security note 1590863, "Potential modification/disclosure of persisted data in CRM-IU", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A malicious user can exploit CRM-IU by using specially crafted inputs to modify database commands. This allows for the retrieval of additional information or the modification of data persisted by the system.

Solution

Implement the attached corrections provided in the SAP Note. Ensure that you follow the correction instructions carefully.

Reason and prerequisites

The vulnerability arises from an SQL injection flaw. The application constructs SQL statements that include user-controllable strings, enabling attackers to manipulate the SQL commands to access or alter database data.

References

Affected components

  • BBPCRM release 400, until SAPKU40018
  • BBPCRM release 500, until SAPKU50019
  • BBPCRM release 520, until SAPKU52011
  • BBPCRM release 600, until SAPKU60010
  • BBPCRM release 700, until SAPKU70010
  • BBPCRM release 701, until SAPKU70105

Full note on SAP: SAP Support Launchpad note 1590863

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More