SAP security note 2022179, "Potential disclosure of persisted data in XX-CSC-PT-FICA", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can exploit the XX-CSC-PT-FICA component by using specially crafted inputs to modify database commands. This can result in the retrieval of additional information persisted by the system through an SQL injection vulnerability.
Solution
SAP recommends installing a solution by applying the latest Support Package. If an immediate solution is required, use the Note Assistant to implement the correction instructions provided in this security note. Detailed instructions can be found on the SAP Service Marketplace.
Reason and prerequisites
The vulnerability is caused by an SQL injection flaw where the code constructs an SQL statement containing strings that can be altered by an attacker. This manipulated SQL statement can then be used to retrieve sensitive data from the database.
References
Full note on SAP: SAP Support Launchpad note 2022179
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
