Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential modification of persisted data in BC-MOB-MI_SER, SAP security note 1579948

SAP Note 1579948
SAP Security Note
High priority

SAP security note 1579948, “Potential modification of persisted data in BC-MOB-MI_SER”, is released on November 13, 2012. Below are the symptom and SAP recommended solution.

ComponentBasis Components > SAP NetWeaver Mobile Infrastructure > Release 2.5 and 7.0 > Mobile Server-side (BC-MOB-MI-SER)
PriorityHigh priority
TypeSAP Security Note
StatusReleased for Customer
Released onNovember 13, 2012

Description

Symptom

A critical vulnerability has been identified in the BC-MOB-MI-SER component of SAP NetWeaver Mobile Infrastructure (Release 2.5 and 7.0). This vulnerability allows a malicious user to exploit specially crafted inputs to perform SQL injection attacks, which can modify database commands and, consequently, alter data persisted by the system.

Solution

The issue is addressed by applying the correction provided in SAP Note 1579948. Ensure that you follow the correction instructions specific to your software component versions.

Full note on SAP: SAP Support Launchpad note 1579948

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More

Three identical server cabinets carrying stacks of code of very different heights beside a measuring rule

ABAP Code Security Scan Cost Drivers

What moves the cost of an ABAP code security scan: custom object counts, effective lines, systems in scope, transport gating, triage and retest.