Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

SQL Injection in SAF-T Portugal, SAP security note 2264508

SAP Note 2264508
SAP Security Note
Medium priority

SAP security note 2264508, “SQL Injection in SAF-T Portugal”, is released on October 27, 2020. Below are the symptom, SAP recommended solution and the affected software components.

PriorityMedium priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released onOctober 27, 2020

Description

Symptom

A critical SQL Injection vulnerability has been identified in the SAF-T Portugal module (XX-CSC-PT-FICA) of SAP. This vulnerability allows attackers to manipulate database commands through specially crafted inputs, potentially leading to unauthorized access and data exposure.

An attacker can exploit the XX-CSC-PT-FICA component by using specially crafted inputs to modify SQL commands. This manipulation can result in the retrieval of additional information stored in the system’s database, leading to potential data breaches and unauthorized data access.

Exploitation of this vulnerability can lead to unauthorized disclosure of persisted data within the affected SAP components, compromising the confidentiality and integrity of the system’s data.

Solution

To mitigate this vulnerability, please implement SAP Note 2264508. This note provides the necessary corrections to address the SQL Injection issue in the SAF-T Portugal module.

CVSS

Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Affected components

  • FI-CA versions: 600, 602, 603, 604, 605, 606, 616, 617, 618, 800

Full note on SAP: SAP Support Launchpad note 2264508

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More