SAP security note 2319506, "SQL Injection Vulnerability in Database Monitors for Oracle". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A SQL Injection vulnerability has been identified in Function Modules STUO_GET_ORA_SYS_TABLE and STUO_GET_ORA_SYS_TABLE_2 within Database Monitors for Oracle. This vulnerability allows attackers to perform unauthorized actions such as reading sensitive data, modifying or deleting database information, executing commands without authorization, and causing Denial of Service (DoS).
Solution
Apply the Correction Instructions provided in SAP Note 2311011.
CVSS
Score 7.2/10 Vector: AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
References
- This security note has been updated. For more detailed information, see SAP Security Note 2418823.
Affected components
- SAP_BASIS (700 to 750)
Full note on SAP: SAP Support Launchpad note 2319506
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
