SAP security note 1928951, "Potential Modification of Persisted Data in BC-SRV-UKM". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An SQL injection vulnerability has been identified in the BC-SRV-UKM component of SAP_BASIS. An attacker can exploit this vulnerability by providing specially crafted inputs that modify database commands, leading to unauthorized modification of data persisted by the system.
Solution
To mitigate this vulnerability, apply the provided correction instructions. These instructions include checks to ensure that functions can only be called by trusted programs within the logical system.
CVSS
Score 6.0 Vector: AV:N/AC:M/PR:S/UI:N/S:U/C:P/I:P/A:P
Affected components
- SAP_BASIS: 701 to 702, 710 to 730, 731, 740
Full note on SAP: SAP Support Launchpad note 1928951
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




