SAP Security Note
Medium priority
SAP security note 2741937, "SQL Injection vulnerability in Central Finance CO", released on December 10, 2019. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Central Finance CO replication allows an attacker to execute crafted database queries, potentially exposing the backend database. Impacts of this SQL Injection vulnerability include reading, modifying or deleting sensitive data, and executing admin-level operations on the database. This vulnerability is only relevant for the Central Finance scenario.
Solution
Implement the attached correction instructions or apply the corresponding Support Package. The correction instructions specify the list of accessible tables via RFC call but indicate no impact on existing functionalities.
CVSS
Score 6.5 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected components
- S4CORE: Versions 100, 101, 102, 103
- SAP_APPL: Versions 600, 602, 603, 604, 605, 606, 616
- SAP_FIN: Versions 617, 618, 720, 730
Full note on SAP: SAP Support Launchpad note 2741937
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
