SAP security note 1587122, “Potential modification of persisted data in FI-CA”. Below are the symptom, SAP recommended solution, references and the affected software components.
Description
Symptom
The issue arises from an SQL injection vulnerability where the code constructs an SQL statement with strings that can be manipulated by a malicious user. This allows the alteration of database commands to modify information stored in the database.
Solution
Apply SAP Security Note 1587122 directly to address the SQL injection vulnerability.
Reason and prerequisites
The vulnerability is due to the improper handling of user inputs in SQL statements within the FI-CA component. No specific prerequisites are mentioned beyond the affected FI-CA versions.
References
Affected components
- FI-CA 464
- FI-CA 471
- FI-CA 472
- FI-CA 600
- FI-CA 602
- FI-CA 603
- FI-CA 604
- FI-CA 605
Full note on SAP: SAP Support Launchpad note 1587122
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




