SAP security note 1590863, "Potential modification/disclosure of persisted data in CRM-IU", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can exploit CRM-IU by using specially crafted inputs to modify database commands. This allows for the retrieval of additional information or the modification of data persisted by the system.
Solution
Implement the attached corrections provided in the SAP Note. Ensure that you follow the correction instructions carefully.
Reason and prerequisites
The vulnerability arises from an SQL injection flaw. The application constructs SQL statements that include user-controllable strings, enabling attackers to manipulate the SQL commands to access or alter database data.
References
- This document refers to 888889 – Automatic checks for security notes using RSECNOTE (outdated)
Affected components
- BBPCRM release 400, until SAPKU40018
- BBPCRM release 500, until SAPKU50019
- BBPCRM release 520, until SAPKU52011
- BBPCRM release 600, until SAPKU60010
- BBPCRM release 700, until SAPKU70010
- BBPCRM release 701, until SAPKU70105
Full note on SAP: SAP Support Launchpad note 1590863
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
