SAP security note 1584573, "Security verdict in SUGM SAUS SUGM_UPG_TYPE_PLUS_DEL_XML", is a program error note released on 06.02.2018. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can exploit the BC-UPG component and use specially crafted inputs to modify database commands. This results in either the retrieval of additional information or the modification of data persisted by the system.
Systems updated using Software Update Manager since 2014 are not affected. If you have used SUM since 2014, set the processing status of this SAP Note to "Not Relevant".
Solution
Implement the correction instructions provided in the SAP Note. If the object from these correction instructions is not available in the system, or if it contains no source code or contains only comment lines, you can ignore the correction instructions.
References
Affected components
- SAP_BASIS: Versions 700 to 702
- SAP_BASIS: Versions 710 to 730
- SAP_BASIS: Versions 800 to 802
Full note on SAP: SAP Support Launchpad note 1584573
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
