SAP Security Note
High priority
SAP security note 1597776, "SEC-102_01 ‘SQL-Injection’: Package VVSRFISL", is a program error note released on April 13, 2012. Below are the symptom and SAP recommended solution.
Description
Symptom
Potential disclosure of persisted data in Statutory Reporting [FS-SR].
Solution
Please implement the attached correction instruction or the corresponding support package. This note disables obsolete code. No testing is required after applying the note.
- Class: ISSR_MIG_SERVICES_BCK
- Method: CONV_MAKE_BCK_SGL
- Parameter: IV_SOURCE_TAB
Reason and prerequisites
The problem is caused by an SQL injection vulnerability. The code composes an SQL statement that contains strings that can be altered by a malicious user. The manipulated SQL statement can then be used to retrieve data from the database.
CVSS
Score 0
Full note on SAP: SAP Support Launchpad note 1597776
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



