Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential modification of persisted data in BC-SRV-UKM, SAP security note 1928951

SAP Note 1928951

SAP security note 1928951, "Potential Modification of Persisted Data in BC-SRV-UKM". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

An SQL injection vulnerability has been identified in the BC-SRV-UKM component of SAP_BASIS. An attacker can exploit this vulnerability by providing specially crafted inputs that modify database commands, leading to unauthorized modification of data persisted by the system.

Solution

To mitigate this vulnerability, apply the provided correction instructions. These instructions include checks to ensure that functions can only be called by trusted programs within the logical system.

CVSS

Score 6.0 Vector: AV:N/AC:M/PR:S/UI:N/S:U/C:P/I:P/A:P

Affected components

  • SAP_BASIS: 701 to 702, 710 to 730, 731, 740

Full note on SAP: SAP Support Launchpad note 1928951

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More