SAP security note 1487973, "Potential disclosure of persisted data in iPPE", was released on December 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A SQL injection vulnerability has been identified in the iPPE function modules. A malicious user can exploit this vulnerability by providing specially crafted inputs to modify database commands, allowing the retrieval of additional information persisted by the system.
Solution
Implement the source code changes described in the advanced corrections provided by SAP. Ensure that all applicable support packages are installed to mitigate this vulnerability.
Affected components
- AP-PPE 200
- AP-PPE 300
- AP-PPE 400
- AP-PPE 404
- AP-PPE 405
- AP-PPE 406
- AP-PPE 616
- AP-PPE 617
- AP-PPE 618
Full note on SAP: SAP Support Launchpad note 1487973
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



