Skip links
Arpine Maghakyan

Arpine Maghakyan

Security Researcher of RedRays.

Potential disclosure and modification of persisted data, SAP security note 1488211

Description

A malicious user can exploit some RFC-enabled function modules in package WRB and use specially crafted inputs to execute arbitrary database commands to retrieve, modify, or remove data persisted by the system.
Depending on the input the user can induce aborts (short dumps) in the system.

Available fix and Supported packages

  • SAP_APPL | 600 | 600
  • SAP_APPL | 602 | 602
  • SAP_APPL | 603 | 603
  • SAP_APPL | 604 | 604
  • SAP_APPL | 605 | 605
  • SAP_APPL 605 | SAPKH60502 |
  • SAP_APPL 600 | SAPKH60019 |
  • SAP_APPL 602 | SAPKH60209 |
  • SAP_APPL 603 | SAPKH60308 |
  • SAP_APPL 604 | SAPKH60409 |

Affected component

    MM-PUR-GF
    Basic Functions

CVSS

Score: 0

Exploit

Exploit is not available.
For detailed information please contact the mail [email protected]

URL

https://launchpad.support.sap.com/#/notes/1488211

TAGS

#SQL-injection
#database

More to explorer