SAP security note 1493435, "Potential disclosure & modification of persisted data in MPN", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can exploit the Manufacturer Part Number (MPN) by using specially crafted inputs to execute arbitrary database commands. This allows the retrieval, modification, or removal of data persisted by the system.
Solution
To address this issue, you should:
- Import the corresponding support package for your SAP ECC version.
- Implement the attached advanced correction manually if necessary.
Before applying this note, ensure that Note 1487337 is implemented.
Reason and prerequisites
The vulnerability arises from an SQL injection flaw. The application constructs SQL statements by incorporating user-controlled input without proper validation, enabling attackers to manipulate these statements to access or alter the database.
Affected components
- SAP ECC 600
- SAP ECC 602
- SAP ECC 603
- SAP ECC 604
- SAP ECC 605
Full note on SAP: SAP Support Launchpad note 1493435
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
