SAP Security Note
High priority
SAP security note 1579948, “Potential modification of persisted data in BC-MOB-MI_SER”, is released on November 13, 2012. Below are the symptom and SAP recommended solution.
Description
Symptom
A critical vulnerability has been identified in the BC-MOB-MI-SER component of SAP NetWeaver Mobile Infrastructure (Release 2.5 and 7.0). This vulnerability allows a malicious user to exploit specially crafted inputs to perform SQL injection attacks, which can modify database commands and, consequently, alter data persisted by the system.
Solution
The issue is addressed by applying the correction provided in SAP Note 1579948. Ensure that you follow the correction instructions specific to your software component versions.
Full note on SAP: SAP Support Launchpad note 1579948
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




