Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential change/disclosure of persisted data, SAP security note 1594984

SAP Note 1594984

SAP security note 1594984, “Potential Change/Disclosure of Persisted Data”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

This security note addresses an SQL injection vulnerability in the XML Data Archiving Service (XML DAS). A malicious user can manipulate database commands, leading to unauthorized data retrieval or modification.

Solution

A comprehensive input validation of XML Data Archiving Services has been implemented to resolve the issue.

Reason and prerequisites

The vulnerability is caused by insufficient input validation in XML DAS, allowing the composition of SQL statements with maliciously altered strings.

References

Affected components

  • SAP-JEE: 6.40
  • SAP_JTECHS: 7.00 to 7.02
  • J2EE-APPS: 7.10 to 7.11

Full note on SAP: SAP Support Launchpad note 1594984

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More