SAP Security Note
SAP security note 1673713, “Potential modification of persisted data in IS-R-STR”, is a note. Below are the symptom, SAP recommended solution, CVSS score and the affected software components.
Description
Symptom
SAP Security Note 1673713 addresses a vulnerability in the IS-R-STR component (Retail Short Text Replacement) that allows an attacker to modify persisted data through specially crafted inputs. This issue arises from an SQL injection vulnerability where manipulated ABAP commands can alter and execute local or remote OS commands.
Solution
Apply the appropriate Hot Package based on your SAP_BASIS version.
CVSS
Score 3.5 Vector: AV:N/AC:M/AU:S/C:N/I:P/A:N
Affected components
- SAP_BASIS versions 620 to 731
Full note on SAP: SAP Support Launchpad note 1673713
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




