SAP security note 1634039, "Potential disclosure of persisted data in CRM-IU-MD-TO", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Attackers can exploit CRM-IU-MD-TO by providing specially crafted inputs that alter SQL statements. This manipulation can result in the retrieval of sensitive information stored within the system’s database.
Solution
- Apply the correction: implement the correction provided in SAP Note 1634039.
- Or install the support package: apply the corresponding support package SAPKU70107.
Workaround: as an interim measure, disable the search functionality for technical objects that utilize customer fields.
Affected components
- CRM-IU-MD-TO (Customer Relationship Management > Utilities Industry > Master Data > Technical Objects)
Full note on SAP: SAP Support Launchpad note 1634039
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
