SAP security note 1527035, "Potential access of saved data in PCO", released on June 14, 2011. Below are the symptom and the affected software components.
Description
Symptom
A malicious user can exploit the PCO by using specially crafted inputs to modify SQL statements, leading to the retrieval of additional data from the database.
Reason and prerequisites
The vulnerability arises from the concatenation of user-supplied strings into SQL statements without proper sanitization, allowing SQL commands to be altered and executed.
CVSS
Score 0
References
Affected components
- FSAPPL Release 100, 200, 300
- BANK-TRBK Release 30, 40
Full note on SAP: SAP Support Launchpad note 1527035
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




