Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential disclosure & modification of persisted data in MPN, SAP security note 1493435

SAP Note 1493435

SAP security note 1493435, "Potential disclosure & modification of persisted data in MPN", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A malicious user can exploit the Manufacturer Part Number (MPN) by using specially crafted inputs to execute arbitrary database commands. This allows the retrieval, modification, or removal of data persisted by the system.

Solution

To address this issue, you should:

  • Import the corresponding support package for your SAP ECC version.
  • Implement the attached advanced correction manually if necessary.

Before applying this note, ensure that Note 1487337 is implemented.

Reason and prerequisites

The vulnerability arises from an SQL injection flaw. The application constructs SQL statements by incorporating user-controlled input without proper validation, enabling attackers to manipulate these statements to access or alter the database.

Affected components

  • SAP ECC 600
  • SAP ECC 602
  • SAP ECC 603
  • SAP ECC 604
  • SAP ECC 605

Full note on SAP: SAP Support Launchpad note 1493435

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More