Low priority
SAP security note 1788562, "Potential Modification/Disclosure of Persisted Data in LO-LIS-REP", is a note released on November 4, 2013. Below are the symptom and SAP recommended solution.
Description
Symptom
An SQL injection vulnerability has been identified in the Logistics Information System – Reporting (LO-LIS-REP) component. This vulnerability allows attackers to exploit standard analyses using specially crafted inputs to manipulate database commands. As a result, unauthorized retrieval of additional information or modification of persisted data within the system is possible.
Solution
Apply the corrections provided in this security note to address the SQL injection vulnerability.
Full note on SAP: SAP Support Launchpad note 1788562
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




