SAP security note 2348055, "SQL Injection vulnerability in addon ST-PI". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Some ST-PI function modules allow an attacker to execute crafted database queries, exposing the backend database.
- Read sensitive data, modify or delete data from the database
- Execute admin-level operations on the database
Solution
Upgrade to ST-PI 2008_1_7* SP15 or ST-PI 740 SP05 to fix the vulnerability. Correction instructions are available for ST-PI 2008_1_7* SP13 and SP14, and for ST-PI 740 SP03 and SP04. Older ST-PI releases should be upgraded to ensure security.
This vulnerability is fixed with ST-PI 2008_1_7* SP15 and ST-PI 740 SP05. The correction instructions attached to this note can be used to fix the vulnerability in earlier support packages. It is strongly recommended to upgrade older releases to mitigate the risk of SQL injection attacks.
CVSS
Score 6.3 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Affected components
- ST-PI 2008_1_7* – versions prior to SP15
- ST-PI 740 – versions prior to SP05
Full note on SAP: SAP Support Launchpad note 2348055
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
