Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential modif./disclosure of persisted data in LO-LIS-REP, SAP security note 1788562

SAP Note 1788562
Low priority

SAP security note 1788562, "Potential Modification/Disclosure of Persisted Data in LO-LIS-REP", is a note released on November 4, 2013. Below are the symptom and SAP recommended solution.

ComponentLogistics Information System – Reporting (LO-LIS-REP)
PriorityCorrection with Low Priority
StatusReleased for Customer
Released onNovember 4, 2013

Description

Symptom

An SQL injection vulnerability has been identified in the Logistics Information System – Reporting (LO-LIS-REP) component. This vulnerability allows attackers to exploit standard analyses using specially crafted inputs to manipulate database commands. As a result, unauthorized retrieval of additional information or modification of persisted data within the system is possible.

Solution

Apply the corrections provided in this security note to address the SQL injection vulnerability.

Full note on SAP: SAP Support Launchpad note 1788562

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More