Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential disclosure of persisted data in CRM-PCF, SAP security note 1583685

SAP Note 1583685
SAP Security Note
Medium priority

SAP security note 1583685, "Potential disclosure of persisted data in CRM-PCF", is a note released on 08.04.2014. Below are the symptom, SAP recommended solution and references.

ComponentCross-Application Components > General Application Functions > People Centric UI Framework
PriorityMedium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on08.04.2014

Description

Symptom

An attacker can exploit CRM-PCF and CA-GTF-PCF by using specially crafted inputs to modify database commands, resulting in the retrieval of additional information persisted by the system.

Solution

Implement the correction instructions attached to this note.

Reason and prerequisites

The issue arises from an SQL injection vulnerability. The vulnerable code constructs an SQL statement that includes strings manipulable by an attacker. This manipulated statement can then be used to extract data from the database.

Security Note 1494284 contains correction instructions which are erroneous. Implementing Security Note 1494284 is a prerequisite for applying this note.

References

Full note on SAP: SAP Support Launchpad note 1583685

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More