Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

SQL Injection vulnerability in XX-CSC-RO-FI, SAP security note 2157355

SAP Note 2157355
SAP Security Note
Medium priority

SAP security note 2157355, "SQL Injection vulnerability in XX-CSC-RO-FI", is a note released on 11.07.2016. Below are the symptom and SAP recommended solution.

ComponentMiscellaneous > Country/Region-Specific Developments > Romania > use FI-LOC-FI-RO
PriorityCorrection with medium priority
TypeSAP Security Note
StatusReleased for Customer
Released on11.07.2016

Description

Symptom

XX-CSC-RO-FI allows an attacker to execute crafted database queries, exposing the backend database.

Some well-known impacts of SQL Injection vulnerability are:

  • Read sensitive data, modify or delete data from the database
  • Execute admin-level operations on the database

Solution

Potentially dangerous user input is now properly escaped before it is used in an SQL statement.

As a general rule, SAP recommends that you install a solution by applying a Support Package. However, if you need to install a solution earlier, use the Note Assistant to implement the correction instruction.

You can find more information about the Note Assistant in SAP Service Marketplace, under Note Assistant.

Full note on SAP: SAP Support Launchpad note 2157355

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More