Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential disclosure and modification of persisted data, SAP security note 1482450

SAP Note 1482450

SAP security note 1482450, "Potential Disclosure and Modification of Persisted Data", is a note. Below are the symptom and SAP recommended solution.

ComponentCRM-IM-IPM (Customer Relationship Management > Media > Intellectual Property Management)
Version701

Description

Symptom

A SQL injection vulnerability exists in the IPM Mass Change template UI of CRM 7.01. A malicious user can exploit this vulnerability by providing specially crafted inputs, allowing them to execute arbitrary database commands. This can lead to the retrieval, modification, or deletion of data persisted by the system.

Solution

To mitigate this vulnerability, apply input validation to the Template ID and implement the correction instructions provided in SAP Note 1482450. Follow these steps:

  • Launch SAP GUI and navigate to transaction SE91.
  • Input CRM_MASS in the ‘Message Class’ field.
  • Click the ‘Change’ button.
  • Locate message 590.
  • Input ‘Template ID is invalid’ in the ‘Message shorttext’ column.
  • Save the changes by clicking the ‘Save’ button.

Full note on SAP: SAP Support Launchpad note 1482450

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More