Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential modification of persisted data in FI-CA, SAP security note 1587122

SAP Note 1587122

SAP security note 1587122, “Potential modification of persisted data in FI-CA”. Below are the symptom, SAP recommended solution, references and the affected software components.

Description

Symptom

The issue arises from an SQL injection vulnerability where the code constructs an SQL statement with strings that can be manipulated by a malicious user. This allows the alteration of database commands to modify information stored in the database.

Solution

Apply SAP Security Note 1587122 directly to address the SQL injection vulnerability.

Reason and prerequisites

The vulnerability is due to the improper handling of user inputs in SQL statements within the FI-CA component. No specific prerequisites are mentioned beyond the affected FI-CA versions.

References

Affected components

  • FI-CA 464
  • FI-CA 471
  • FI-CA 472
  • FI-CA 600
  • FI-CA 602
  • FI-CA 603
  • FI-CA 604
  • FI-CA 605

Full note on SAP: SAP Support Launchpad note 1587122

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More

Three identical server cabinets carrying stacks of code of very different heights beside a measuring rule

ABAP Code Security Scan Cost Drivers

What moves the cost of an ABAP code security scan: custom object counts, effective lines, systems in scope, transport gating, triage and retest.