SAP security note 2331141, "SQL Injection vulnerability in SAP CIS Country Localization XML Generator". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP CIS Country Localization XML Generator allows an attacker to execute crafted database queries, exposing the backend database.
Read sensitive data from database.
Solution
The program now screens the user input for proper data submission and removes dangerous SQL statements. Apply the indicated Support Packages (SP) or implement correction instructions using transaction SNOTE.
CVSS
Score 3.1 / 10 Vector: AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
References
This note refers to
Affected components
- SAP_APPL 600
- SAP_APPL 602
- SAP_APPL 603
- SAP_APPL 604
- SAP_APPL 605
- SAP_APPL 606
- SAP_APPL 616
- SAP_FIN 617
- SAP_FIN 618
- SAP_FIN 700
- SAP_FIN 720
- SAP_FIN 730
- S4CORE 100
Full note on SAP: SAP Support Launchpad note 2331141
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



