Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential disclosure of persisted data in iPPE, SAP security note 1487973

SAP Note 1487973

SAP security note 1487973, "Potential disclosure of persisted data in iPPE", was released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentApplication Platform > Integrated Product and Process Engineering (AP-PPE)
PriorityHigh
StatusReleased for Customer
Released onDecember 14, 2010

Description

Symptom

A SQL injection vulnerability has been identified in the iPPE function modules. A malicious user can exploit this vulnerability by providing specially crafted inputs to modify database commands, allowing the retrieval of additional information persisted by the system.

Solution

Implement the source code changes described in the advanced corrections provided by SAP. Ensure that all applicable support packages are installed to mitigate this vulnerability.

Affected components

  • AP-PPE 200
  • AP-PPE 300
  • AP-PPE 400
  • AP-PPE 404
  • AP-PPE 405
  • AP-PPE 406
  • AP-PPE 616
  • AP-PPE 617
  • AP-PPE 618

Full note on SAP: SAP Support Launchpad note 1487973

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More