SAP security note 2453642, “SQL Injection vulnerability in SAP NetWeaver”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP NetWeaver contains a SQL Injection vulnerability that allows an attacker to execute crafted database queries, potentially exposing the backend database. This can lead to unauthorized reading of sensitive data, modification or deletion of data, and execution of administrative operations on the database.
Solution
The affected function module has been hardened to prevent unauthorized access. The solution is included in the relevant Support Packages for the affected component.
CVSS
Score 4.7 Vector: AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
References
This note refers to
Affected components
- SAP Business Warehouse > Basis System and Installation > BW Database Platforms (BW-SYS-DB)
Full note on SAP: SAP Support Launchpad note 2453642
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
