Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

SQL injection vulnerability in SAP NetWeaver, SAP security note 2051717

SAP Note 2051717
Medium priority

SAP security note 2051717, “SQL injection vulnerability in SAP NetWeaver”, was released on September 15, 2017. Below are the symptom, SAP recommended solution and the affected software components.

ComponentSAP_BASIS
PriorityMedium priority
StatusReleased for Customer
Released onSeptember 15, 2017

Description

Symptom

A SQL injection vulnerability has been identified in SAP NetWeaver, allowing malicious users to execute targeted database queries. This can potentially expose the back-end database, leading to severe security impacts.

The SQL injection vulnerability can result in:

  • Data Exposure: Unauthorized reading of sensitive data.
  • Data Modification: Alteration or deletion of data within the database.
  • Administrative Operations: Execution of operations at the admin level on the database.

Solution

To mitigate this vulnerability, implement the correction instructions or import the relevant Support Package. This will enforce proper checks on input parameters, eliminating the risk of SQL injection.

Affected components

  • SAP_BASIS 700 to 702
  • SAP_BASIS 710 to 711
  • SAP_BASIS 730
  • SAP_BASIS 731
  • SAP_BASIS 740

Full note on SAP: SAP Support Launchpad note 2051717

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More