High
SAP security note 1831463, “Potential modification of persisted data in upgrade tools”, was released on June 19, 2013. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A critical SQL injection vulnerability has been identified in SAP’s upgrade tools. This vulnerability allows attackers to send specially crafted inputs to modify database commands, potentially leading to unauthorized data retrieval or modification.
Solution
- Apply Correction Instructions: Remove the vulnerable code entirely. If your system is already at the required Support Package level, the vulnerable object may no longer exist.
- For SAP_BASIS Releases 731 and 740: If not using a fixed version of the Software Update Manager, import the attached transport request.
CVSS
Score 4.9 Vector: AV:N/AC:M/AU:S/C:N/I:P/A:P
Affected components
- SAP_BASIS: 46A to 46D, 610 to 640, 700 to 702, 710 to 730, 731, 740
Full note on SAP: SAP Support Launchpad note 1831463
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



