SAP Security Note
High priority
SAP security note 1511561, “Saved data may be read in the HR Management system”, is a program error note released on 14.12.2010. Below are the symptom, reason and prerequisites, SAP recommended solution, CVSS score and references.
Description
Symptom
An attacker can prompt the SAP Human Resource Management System to reveal additional data by making selective entries during the call of RFC-enabled function modules.
Solution
The solution provided in this note ensures that the two RFC-enabled function modules can read only HR data from specified tables.
The "Reference to Support Packages" section specifies the Support Packages that contain the corrections.
Alternatively, you can implement the attached correction instructions.
Reason and prerequisites
This problem is caused by an SQL injection issue. In the source code, an SQL statement consists of strings in which an attacker can obtain control over the content of a substring. Through this, the resulting complete statement can be manipulated and, therefore, the database can be prompted to output additional data.
CVSS
Score 0
References
This note refers to
Full note on SAP: SAP Support Launchpad note 1511561
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



