SAP security note 1594984, “Potential Change/Disclosure of Persisted Data”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This security note addresses an SQL injection vulnerability in the XML Data Archiving Service (XML DAS). A malicious user can manipulate database commands, leading to unauthorized data retrieval or modification.
Solution
A comprehensive input validation of XML Data Archiving Services has been implemented to resolve the issue.
Reason and prerequisites
The vulnerability is caused by insufficient input validation in XML DAS, allowing the composition of SQL statements with maliciously altered strings.
References
Affected components
- SAP-JEE: 6.40
- SAP_JTECHS: 7.00 to 7.02
- J2EE-APPS: 7.10 to 7.11
Full note on SAP: SAP Support Launchpad note 1594984
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
