Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

SQL Injection vulnerability in Central Finance CO, SAP security note 2741937

SAP Note 2741937
SAP Security Note
Medium priority

SAP security note 2741937, "SQL Injection vulnerability in Central Finance CO", released on December 10, 2019. Below are the symptom, SAP recommended solution and the affected software components.

ComponentFinancial Accounting > Central Finance > Replication of CO Internal Postings
PriorityMedium priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released onDecember 10, 2019

Description

Symptom

Central Finance CO replication allows an attacker to execute crafted database queries, potentially exposing the backend database. Impacts of this SQL Injection vulnerability include reading, modifying or deleting sensitive data, and executing admin-level operations on the database. This vulnerability is only relevant for the Central Finance scenario.

Solution

Implement the attached correction instructions or apply the corresponding Support Package. The correction instructions specify the list of accessible tables via RFC call but indicate no impact on existing functionalities.

CVSS

Score 6.5 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected components

  • S4CORE: Versions 100, 101, 102, 103
  • SAP_APPL: Versions 600, 602, 603, 604, 605, 606, 616
  • SAP_FIN: Versions 617, 618, 720, 730

Full note on SAP: SAP Support Launchpad note 2741937

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More