Skip links
🔥🔥🔥 Join us for our upcoming training session at Black Hat MEA: "Securing SAP Systems: Expert Insights and Penetration Testing Techniques" 🛡️🔍

Potential deletion of persisted data in CRMD_FM_ACL_SV, SAP security note 1482345

Description

A malicious user can exploit CRMD_FM_ACL_SV and use specially crafted inputs to execute arbitrary database commands to remove data persisted by the system.

Available fix and Supported packages

  • BBPCRM | 600 | 600
  • BBPCRM | 700 | 700
  • BBPCRM | 701 | 701
  • BBPCRM 600 | SAPKU60008 |
  • BBPCRM 701 | SAPKU70102 |
  • BBPCRM 700 | SAPKU70008 |

Affected component

    CRM-FM-ACL
    Accruals

CVSS

Score: 0

Exploit

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1482345

TAGS

#Sales-volumes-load
#ERP-discount-load
#External-settlements
#Parallel-processing
#Fund-posting
#Accruals-runSQL-Injection

How to detect over 4100 vulnerabilities in SAP Systems?

More to explorer