SAP security note 1482450, "Potential Disclosure and Modification of Persisted Data", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
A SQL injection vulnerability exists in the IPM Mass Change template UI of CRM 7.01. A malicious user can exploit this vulnerability by providing specially crafted inputs, allowing them to execute arbitrary database commands. This can lead to the retrieval, modification, or deletion of data persisted by the system.
Solution
To mitigate this vulnerability, apply input validation to the Template ID and implement the correction instructions provided in SAP Note 1482450. Follow these steps:
- Launch SAP GUI and navigate to transaction SE91.
- Input CRM_MASS in the ‘Message Class’ field.
- Click the ‘Change’ button.
- Locate message 590.
- Input ‘Template ID is invalid’ in the ‘Message shorttext’ column.
- Save the changes by clicking the ‘Save’ button.
Full note on SAP: SAP Support Launchpad note 1482450
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



