Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential modif./disclosure of persisted data in Agentry Server, SAP security note 2238932

SAP Note 2238932
Medium priority

SAP security note 2238932, "Potential Modification/Disclosure of Persisted Data in Agentry Server", was released on December 8, 2015. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBusiness Mobile > SAP Mobile Platform on Premise > SAP Mobile On Premise Security (MOB-ONP-SEC)
PriorityCorrection with medium priority
StatusReleased for Customer
Released onDecember 8, 2015

Description

Symptom

An attacker can manipulate SQL statements by altering input strings, leading to unauthorized data access or modification.

Solution

To address this vulnerability, upgrade to the following versions:

  • SAP Mobile Platform: from 3.0 SP08 or earlier to 3.0 SP09 or above.
  • SAP Mobile Platform: from 2.3 SP06 PL01 or earlier to 2.3 SP06 PL02 or above.
  • Agentry 6.0 is out of maintenance and should be upgraded to SAP Mobile Platform 3.0 SP09 or above. Alternatively, upgrading to SMP 2.3 SP06 PL02 will resolve the vulnerability, but note that SMP 2.3 is scheduled to go out of maintenance on 31-Dec-2016, necessitating a further upgrade to SMP 3.

CVSS

Score 6.5 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Affected components

  • AGENTRYSRV versions 6.0 and 6.1

Full note on SAP: SAP Support Launchpad note 2238932

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More