Medium priority
SAP security note 2238932, "Potential Modification/Disclosure of Persisted Data in Agentry Server", was released on December 8, 2015. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can manipulate SQL statements by altering input strings, leading to unauthorized data access or modification.
Solution
To address this vulnerability, upgrade to the following versions:
- SAP Mobile Platform: from 3.0 SP08 or earlier to 3.0 SP09 or above.
- SAP Mobile Platform: from 2.3 SP06 PL01 or earlier to 2.3 SP06 PL02 or above.
- Agentry 6.0 is out of maintenance and should be upgraded to SAP Mobile Platform 3.0 SP09 or above. Alternatively, upgrading to SMP 2.3 SP06 PL02 will resolve the vulnerability, but note that SMP 2.3 is scheduled to go out of maintenance on 31-Dec-2016, necessitating a further upgrade to SMP 3.
CVSS
Score 6.5 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P
Affected components
- AGENTRYSRV versions 6.0 and 6.1
Full note on SAP: SAP Support Launchpad note 2238932
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
