SAP security note 1371602, "Potential Reading or Changing of Data in FS-RI (Claims)". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
- SQL Injection: Allows unauthorized modification or disclosure of data through manipulated SQL statements.
- Hard-coded Username: Can lead to unintended changes in program behavior if authenticated with the hard-coded credentials.
- Path Manipulation: Enables writing of arbitrary data to remote systems or overwriting existing data.
- Code Injection: Permits execution of malicious code, potentially altering system behavior and compromising data integrity.
Solution
Apply the source code corrections by installing the relevant support packages for the FS-RI (Claims) component.
Using transaction SE38, mark the following programs as obsolete by changing their text elements and activating the change: /MSG/R_ABR_KTOZUO_START, /MSG/R_A_B_AUFBAU_STAT_TABS, /MSG/R_FSRI_DATA_DOWNLOAD, /MSG/R_LSMW_PROJ_CONV_472_600.
Affected components
- FS-RI (Financial Services – Re-Insurance > Claims): Versions 472, 600, 650, 660
Full note on SAP: SAP Support Launchpad note 1371602
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
