SAP security note 1568817, "Potential Modification or Disclosure of Persistent Data in FS-BA", is released on July 12, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can exploit the FS-BA-AN-FSP module using specially crafted inputs to alter database statements. This can result in the retrieval of additional information or modification of data persisted by the system.
Solution
Please install the provided correction via the support package or using the Note Assistant.
Reason and prerequisites
The issue arises from an SQL injection vulnerability where the code constructs SQL statements with input strings that can be manipulated by a malicious user. This allows the attacker to modify the SQL statement to access or alter data.
CVSS
Score 0
Affected components
- FSAPPL (Financial Services > Bank Analyzer), Version 300
Full note on SAP: SAP Support Launchpad note 1568817
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
