SAP security note 2129609, "Potential modification/disclosure of persisted data in EP JDBC Connector". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can exploit the EP JDBC Connector by using specially crafted inputs to modify database commands. This vulnerability can lead to the retrieval of additional information or the modification of data persisted by the system.
Solution
Apply the provided patch available through the following links.
CVSS
Score 6.5 / 10 Vector: AV:N/AC:L/PR:S/UI:None/S:Unchanged/C:P/I:P/A:P
References
- Central Note for Visual Composer for SAP NW7.30 SP14
- SP Central Note for Visual Composer for SAP NW7.0 EhP1 SP18
- SP Central Note for Visual Composer for SAP NW7.00 SP33
- SP Central Note for Visual Composer SAP NW7.10 EhP01 SP15
- SP Central Note for Visual Composer for SAP NW7.10 SP20
Affected components
- Enterprise Portal > Connector Framework Infrastructure > Portal Connector to JDBC DataSource (EP-CON-DB)
- EP CONNECTIVITY 7.00 to 7.02
- EP CONNECTIVITY 7.10 to 7.11
- EP CONNECTIVITY 7.20
- EP CONNECTIVITY 7.30
- EP CONNECTIVITY 7.31
- EP CONNECTIVITY 7.40
- EP CONNECTIVITY 7.50
Full note on SAP: SAP Support Launchpad note 2129609
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
