SAP security note 1710213, "KORR: Possible disclosure of persisted data in FS-RI", is a note released on January 13, 2015. Below are the symptom and SAP recommended solution.
Description
Symptom
A vulnerability has been identified in the FS-RI-B component (Financial Services > Re-Insurance > Reinsurance Basis) of SAP. This SQL injection vulnerability allows an attacker to exploit specially crafted inputs to modify database commands, potentially leading to the unauthorized retrieval of persisted data from the system.
Solution
To address this vulnerability, apply the necessary corrections as outlined in the SAP Security Note. Manual tasks are required to implement the solution effectively. Detailed correction instructions are provided within the note.
Full note on SAP: SAP Support Launchpad note 1710213
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
