SAP Security Note
High priority
SAP security note 1487212, "Potential Modification or Disclosure of Persisted Data in PLM-RM", released on February 3, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This security note addresses an SQL injection vulnerability within the PLM-RM component. A malicious user can exploit this vulnerability by supplying specially crafted inputs that modify database commands. This can lead to unauthorized retrieval of additional information or modification of persisted data within the system.
Solution
Implement the source code changes as outlined in the advance corrections provided with this security note. Detailed correction instructions include creating subroutines and modifying existing includes within the SAP system using transaction SE38.
References
Affected components
- RMGMT (210)
- EA-APPL (200, 500, 600, 602, 603, 604, 605)
Full note on SAP: SAP Support Launchpad note 1487212
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




