Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential disclosure of persisted data in LO-MD-BP-CM & LO-MD-BP-VM, SAP security note 2088593

SAP Note 2088593SAP Security NoteMedium priority

SAP security note 2088593, "Potential Disclosure of Persisted Data in LO-MD-BP-CM & LO-MD-BP-VM", released on 10.07.2017. Below are the symptom, SAP recommended solution and the affected software components.

ComponentLogistics – General > Logistics Basic Data > Business Partners > Customer Master (LO-MD-BP-CM)
PriorityMedium priority
TypeSAP Security Note
StatusReleased for Customer
Released on10.07.2017

Description

Symptom

An attacker can exploit LO-MD-BP-CM & LO-MD-BP-VM by using specially crafted inputs to modify database commands. This can result in the retrieval of additional information persisted by the system. Additionally, this SAP note introduces new switchable authorization checks for RFC function modules in LO-MD-BM-CM & LO-MD-BP-VM.

Solution

To address the vulnerability, implement the attached correction instructions provided in this SAP note. The new authorization checks are inactive by default to maintain compatibility with existing processes and can be activated manually via transaction SACF.

Affected function modules:

  • BAPI_VENDOR_FIND
  • BAPI_CUSTOMER_FIND

Reason and prerequisites

The vulnerability arises from an SQL injection flaw where the code composes SQL statements with strings that can be manipulated by an attacker. Remote Function Calls (RFC) to certain function modules were previously only protected by the authorization object S_RFC, which may not suffice to ensure secure execution. To mitigate this, new switchable authorization checks have been implemented.

References

Affected components

  • Logistics – General > Logistics Basic Data > Business Partners > Customer Master (LO-MD-BP-CM), SAP_APPL 600 to 617

Full note on SAP: SAP Support Launchpad note 2088593

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More