SAP Security Note
Medium priority
SAP security note 2157355, "SQL Injection vulnerability in XX-CSC-RO-FI", is a note released on 11.07.2016. Below are the symptom and SAP recommended solution.
Description
Symptom
XX-CSC-RO-FI allows an attacker to execute crafted database queries, exposing the backend database.
Some well-known impacts of SQL Injection vulnerability are:
- Read sensitive data, modify or delete data from the database
- Execute admin-level operations on the database
Solution
Potentially dangerous user input is now properly escaped before it is used in an SQL statement.
As a general rule, SAP recommends that you install a solution by applying a Support Package. However, if you need to install a solution earlier, use the Note Assistant to implement the correction instruction.
You can find more information about the Note Assistant in SAP Service Marketplace, under Note Assistant.
Full note on SAP: SAP Support Launchpad note 2157355
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
