Description
An attacker can exploit Mitigation process in GRC Access Control by executing crafted database queries, exposing the backend database.
Some well-known impacts of SQL Injection vulnerability are –
- read sensitive data , modify or delete data from database
- execute admin level operations on database
Available fix and Supported packages
- GRCFND_A | V1000 | V1000
- GRCFND_A | V1100 | V1100
- GRCFND_A | V8000 | V8000
- GRCFND_A V1000 | SAPK-V1026INGRCFNDA |
- GRCFND_A V1100 | SAPK-V1119INGRCFNDA |
- GRCFND_A V8000 | SAPK-V8005INGRCFNDA |
Affected component
- GRC-SAC-ARA
Access Risk Analysis
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/2491763