SAP security note 2088593, "Potential Disclosure of Persisted Data in LO-MD-BP-CM & LO-MD-BP-VM", released on 10.07.2017. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can exploit LO-MD-BP-CM & LO-MD-BP-VM by using specially crafted inputs to modify database commands. This can result in the retrieval of additional information persisted by the system. Additionally, this SAP note introduces new switchable authorization checks for RFC function modules in LO-MD-BM-CM & LO-MD-BP-VM.
Solution
To address the vulnerability, implement the attached correction instructions provided in this SAP note. The new authorization checks are inactive by default to maintain compatibility with existing processes and can be activated manually via transaction SACF.
Affected function modules:
- BAPI_VENDOR_FIND
- BAPI_CUSTOMER_FIND
Reason and prerequisites
The vulnerability arises from an SQL injection flaw where the code composes SQL statements with strings that can be manipulated by an attacker. Remote Function Calls (RFC) to certain function modules were previously only protected by the authorization object S_RFC, which may not suffice to ensure secure execution. To mitigate this, new switchable authorization checks have been implemented.
References
- 2030997 – Switchable Authorization Checks for RFC in FI-AP-AP
- 2023449 – Switchable Authorization Checks for RFC in FI, FI-AP-AP, FI-AR-AR, FI-BL-MD-BK
- 2078596 – Further Improvements for RFC Security
- 2008727 – Securing Remote Function Calls (RFC)
- 1922712 – SLDW: FAQ: Supplementary Notes for Whitelist Maintenance
Affected components
- Logistics – General > Logistics Basic Data > Business Partners > Customer Master (LO-MD-BP-CM), SAP_APPL 600 to 617
Full note on SAP: SAP Support Launchpad note 2088593
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




