Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Possible disclosure of saved data in FIN-SEM BPS, SAP security note 1497451

SAP Note 1497451

SAP security note 1497451, “Possible disclosure of saved data in FIN-SEM BPS”, is a note. Below is the security information published by SAP for this note.

Description

Symptom

An attacker can use targeted entries to prompt SEM planning to disclose additional data or change saved data in the database.

Reason and prerequisites

The problem occurs due to an SQL injection issue. In the code, an SQL statement is composed of strings, and an attacker can gain control over the content of a substring. This means that the resulting overall statement can be manipulated and data can be changed in the database, or the database can be prompted to disclose additional data.

Solution

Implement the corrections.

Affected Software Components:

  • SEM-BW (Versions: 350, 400, 600, 700, 602, 603, 604, 605, 634)

Support Package:

Download Links:

Translation Availability:

References: This document does not currently reference other SAP Notes or KBAs, nor is it referenced by other documents.

Full note on SAP: SAP Support Launchpad note 1497451

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More