SAP security note 1483158, "Potential disclosure of data in object data exchange monitor", is a program error note released on September 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can exploit the object data exchange monitor and use specially crafted inputs to execute arbitrary database commands to retrieve data persisted by the system.
Solution
Implement the correction instructions for your release. You can Download for SNOTE or access the PDF Version.
Reason and prerequisites
The problem is caused by an SQL injection vulnerability. The code composes an SQL statement including strings that can be altered by a malicious user. The manipulated SQL statement can then be used to retrieve additional information from the database.
References
- SAP Note 1468574 – SAP CRM 2005 – SP Stack 17
Affected components
- BBPCRM 500
- BBPCRM 520
- BBPCRM 600
- BBPCRM 700
- BBPCRM 701
Full note on SAP: SAP Support Launchpad note 1483158
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
