Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential reading or changing of data in FS-RI (Claims), SAP security note 1371602

SAP Note 1371602

SAP security note 1371602, "Potential Reading or Changing of Data in FS-RI (Claims)". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

  • SQL Injection: Allows unauthorized modification or disclosure of data through manipulated SQL statements.
  • Hard-coded Username: Can lead to unintended changes in program behavior if authenticated with the hard-coded credentials.
  • Path Manipulation: Enables writing of arbitrary data to remote systems or overwriting existing data.
  • Code Injection: Permits execution of malicious code, potentially altering system behavior and compromising data integrity.

Solution

Apply the source code corrections by installing the relevant support packages for the FS-RI (Claims) component.

Using transaction SE38, mark the following programs as obsolete by changing their text elements and activating the change: /MSG/R_ABR_KTOZUO_START, /MSG/R_A_B_AUFBAU_STAT_TABS, /MSG/R_FSRI_DATA_DOWNLOAD, /MSG/R_LSMW_PROJ_CONV_472_600.

Affected components

  • FS-RI (Financial Services – Re-Insurance > Claims): Versions 472, 600, 650, 660

Full note on SAP: SAP Support Launchpad note 1371602

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More