Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential modification of persisted data in CL_UPG_SHDCLONE, SAP security note 1637073

SAP Note 1637073

SAP security note 1637073, "Potential modification of persisted data in CL_UPG_SHDCLONE", was released on December 22, 2015. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Upgrade – general > Upgrade Tools (SUM) > Upgrade tools for ABAP
StatusReleased for Customer
Released onDecember 22, 2015

Description

Symptom

An attacker can exploit CL_UPG_SHDCLONE and use specially crafted inputs to modify database commands, resulting in the modification of data persisted by the system.

Solution

All SUM versions delivered after January 2012 contain the corrected version of the objects.

Therefore, this security note is no longer relevant!

Reason and prerequisites

The problem is caused by an SQL injection vulnerability. The code composes an SQL statement that contains strings that can be altered by an attacker. The manipulated SQL statement can then be used to modify information in the database.

Full note on SAP: SAP Support Launchpad note 1637073

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More