Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

SQL Injection vulnerability in addon ST-PI, SAP security note 2348055

SAP Note 2348055

SAP security note 2348055, "SQL Injection vulnerability in addon ST-PI". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Some ST-PI function modules allow an attacker to execute crafted database queries, exposing the backend database.

  • Read sensitive data, modify or delete data from the database
  • Execute admin-level operations on the database

Solution

Upgrade to ST-PI 2008_1_7* SP15 or ST-PI 740 SP05 to fix the vulnerability. Correction instructions are available for ST-PI 2008_1_7* SP13 and SP14, and for ST-PI 740 SP03 and SP04. Older ST-PI releases should be upgraded to ensure security.

This vulnerability is fixed with ST-PI 2008_1_7* SP15 and ST-PI 740 SP05. The correction instructions attached to this note can be used to fix the vulnerability in earlier support packages. It is strongly recommended to upgrade older releases to mitigate the risk of SQL injection attacks.

CVSS

Score 6.3 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Affected components

  • ST-PI 2008_1_7* – versions prior to SP15
  • ST-PI 740 – versions prior to SP05

Full note on SAP: SAP Support Launchpad note 2348055

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More