Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

SQL Injection vulnerability in SAP CIS Country Localization XML Generator, SAP security note 2331141

SAP Note 2331141

SAP security note 2331141, "SQL Injection vulnerability in SAP CIS Country Localization XML Generator". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP CIS Country Localization XML Generator allows an attacker to execute crafted database queries, exposing the backend database.

Read sensitive data from database.

Solution

The program now screens the user input for proper data submission and removes dangerous SQL statements. Apply the indicated Support Packages (SP) or implement correction instructions using transaction SNOTE.

CVSS

Score 3.1 / 10 Vector: AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

References

Affected components

  • SAP_APPL 600
  • SAP_APPL 602
  • SAP_APPL 603
  • SAP_APPL 604
  • SAP_APPL 605
  • SAP_APPL 606
  • SAP_APPL 616
  • SAP_FIN 617
  • SAP_FIN 618
  • SAP_FIN 700
  • SAP_FIN 720
  • SAP_FIN 730
  • S4CORE 100

Full note on SAP: SAP Support Launchpad note 2331141

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More