Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential modification or disclosure of persisted data, SAP security note 1515822

SAP Note 1515822
SAP Security Note
High priority

SAP security note 1515822, "Potential modification or disclosure of persisted data", is a program error note released on 13.09.2011. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBC-SRV-FSI
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version7
StatusReleased for Customer
Released on13.09.2011
LanguageEnglish

Description

Symptom

Potential modification or disclosure of persisted data in SAP_BASIS (FSI).

A malicious user can exploit SAP_BASIS (FSI) and use specially crafted inputs to modify data-base commands, resulting in either the retrieval of additional information or modification of data persisted by the system.

Solution

The correction consists of removal of potentially exploitable coding by changing the data type of the SQL statement.

Please apply correction 0120031469 0002935945 2010.

Reason and prerequisites

The problem is caused by an SQL injection vulnerability. The code composes an SQL statement including strings that can be altered by a malicious user. The manipulated SQL statement can then be used to retrieve additional data from the database or modify it.

Affected components

  • SAP_BASIS 711

Full note on SAP: SAP Support Launchpad note 1515822

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More